Rule ID
|
Type
|
Signature
|
Tag
|
Score
|
Match zone
|
127 | 1 | RL | nwaftest | Other | 12 | BODY|URL|ARGS|HEADERS |
93 | 30 | RL | {{ | Injection | 2 | BODY |
212 | 31 | RLx | (\d+\s*,\s*){4,} | SQLi | 4 | BODY|URL|ARGS|HEADERS |
194 | 32 | RLx | \W&&\W | SQLi | 2 | BODY|URL|ARGS|HEADERS |
14 | 33 | RLx | \W@@\w | SQLi | 2 | BODY|URL|ARGS|HEADERS |
55 | 34 | RLx | \W\|\|\W | SQLi | 2 | BODY|URL|ARGS |
120 | 35 | RLx | \{\{.+\}\} | Injection | 8 | ARGS |
88 | 36 | RL | $( | Injection | 2 | BODY|URL|ARGS|HEADERS |
217 | 37 | RL | ${ | Injection | 2 | BODY|URL|ARGS|HEADERS |
60 | 39 | RL | /* | SQLi | 1 | BODY|URL|ARGS|Cookie|User-agent |
229 | 40 | RL | */ | SQLi | 1 | BODY|URL|ARGS|Cookie|User-agent |
9 | 51 | RL | ; | SQLi | 2 | URL|ARGS |
99 | 52 | RL | ' | SQLi | 2 | URL|ARGS|User-Agent |
253 | 53 | RL | ? | Evasion | 2 | URL|ARGS|User-agent |
206 | 54 | RL | ['# | RCE | 8 | URL |
150 | 55 | RL | \'% | SQLi | 2 | BODY|URL|ARGS |
222 | 56 | RL | %\' | SQLi | 2 | BODY|URL|ARGS |
123 | 57 | RLx | (\.)+(\\|\/)+(\.)+(\\|\/)+ | LFI | 8 | BODY|URL|ARGS|HEADERS |
251 | 58 | RL | =\" | SQLi | 2 | BODY|URL|ARGS |
86 | 59 | RL | =\' | SQLi | 2 | BODY|URL|ARGS |
220 | 60 | RL | *\' | SQLi | 4 | BODY|URL|ARGS |
139 | 61 | RL | != | SQLi | 6 | URL|ARGS |
108 | 66 | RL | \\ | Evasion | 2 | BODY|URL|ARGS |
48 | 67 | RL | ../ | Injection | 8 | BODY|URL|ARGS|HEADERS |
14 | 68 | RL | -- | SQLi | 2 | BODY|URL|ARGS|User-agent |
78 | 69 | RL | # | SQLi | 1 | BODY|URL|ARGS|Cookie|User-agent |
107 | 71 | RL | ..\..\ | LFI | 8 | BODY|URL|ARGS|HEADERS |
6 | 74 | RLx | \\x[0-9a-z]{2,2} | Evasion | 0 | BODY|URL|ARGS|HEADERS|MLA |
141 | 76 | RLx | (\\|%)u[0-9a-f]{4,4} | Evasion | 0 | BODY|URL|ARGS|HEADERS|MLA |
41 | 77 | RL | ././ | LFI | 8 | BODY|URL|ARGS|HEADERS |
219 | 98 | RLx | [&=<]\.0 | XSS | 6 | BODY|URL|ARGS |
217 | 99 | RLx | [\^<>]0\. | XSS | 6 | BODY|URL|ARGS |
186 | 100 | WLx | sitemap[\w\-\.]+\.gz$ | WL | 0 | URL |
231 | 101 | WLx | (\d+\s*,\s*){4,} | WL | 0 | Cookie|Referer |
211 | 104 | WLx | utm_referrer=https?://\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3} | WL | 0 | ARGS |
208 | 105 | WLx | \-+\w | WL | 0 | Content-Type |
27 | 106 | WL | xn--p1ai | WL | 0 | BODY|URL|ARGS|HEADERS |
136 | 109 | WL | ?from= | WL | 0 | ARGS |
135 | 110 | WL | <?xml | WL | 0 | BODY |
49 | 111 | WLx | \{\{[a-z0-9.]+\}\} | WL | 0 | ARGS |
194 | 500 | RL | /.source | XSS | 12 | BODY|URL|ARGS|HEADERS |
38 | 502 | RLx | (\s|\.)src(\s|\+)*= | XSS | 2 | BODY|URL|ARGS|HEADERS |
27 | 504 | RLx | (^|\W)eval\(|@eval\W | XSS | 12 | BODY|URL|ARGS|HEADERS |
77 | 505 | RLx | <svg(\s|\+) | XSS | 4 | BODY|URL|ARGS|HEADERS |
144 | 508 | RLx | (^|\W)alert\/?(\.(source|call|apply|bind|valueof))?[\(\`\&\]] | XSS | 8 | BODY|URL|ARGS|HEADERS |
44 | 509 | RL | symbol.replace | XSS | 8 | BODY|URL|ARGS|HEADERS |
249 | 510 | RLx | array\.(map|from|prototype) | XSS | 8 | BODY|URL|ARGS|HEADERS |
166 | 511 | RLx | (^|\W)document(\.[a-z]+)+\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
45 | 512 | RL | </noscript | XSS | 4 | BODY|URL|ARGS|HEADERS |
85 | 513 | RL | </xmp | XSS | 4 | BODY|URL|ARGS|HEADERS |
137 | 514 | RL | </style | XSS | 4 | BODY|URL|ARGS|HEADERS |
235 | 515 | RL | </script | XSS | 12 | BODY|URL|ARGS|HEADERS |
78 | 516 | RLx | <img(\s|\+) | XSS | 2 | BODY|URL|ARGS|HEADERS |
43 | 517 | RLx | <base(\s|\+) | XSS | 4 | BODY|URL|ARGS|HEADERS |
44 | 518 | RLx | <i?frame\W | XSS | 6 | BODY|URL|ARGS|HEADERS |
107 | 528 | RLx | on(error|cut|begin|wheel|blur|change|input|reset|select|down|keypress|keyup|paste|copy|toggle)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
237 | 532 | RLx | onmouse(down|enter|leave|move|out|over|up|wheel)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
218 | 534 | RL | </title | XSS | 2 | BODY|URL|ARGS|HEADERS |
144 | 535 | RL | svg> | XSS | 4 | BODY|URL|ARGS|HEADERS |
18 | 536 | RL | << | XSS | 4 | URL|ARGS |
185 | 537 | RLx | <script(\s|\+|\/|\>) | XSS | 12 | BODY|URL|ARGS|HEADERS |
28 | 538 | RL | >> | XSS | 4 | URL|ARGS |
110 | 540 | RLx | on(aux|dbl)?click(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
155 | 542 | RLx | ontouchcancel(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
120 | 543 | RLx | (^|\W)set(Timeout|Interval|Immediate)\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
113 | 544 | RLx | (^|\W)execscript\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
123 | 545 | RL | crypto.generateCRMFRequest | XSS | 12 | BODY|URL|ARGS|HEADERS |
76 | 548 | RL | Range.createContextualFragment | XSS | 12 | BODY|URL|ARGS|HEADERS |
202 | 549 | RLx | window[?]?\.(location|alert|name) | XSS | 12 | BODY|URL|ARGS|HEADERS |
237 | 550 | RLx | document[.;](location|domain|cookie) | XSS | 8 | BODY|URL|ARGS|HEADERS |
46 | 551 | RLx | (^|\W)location\.(assign|reload|replace|tostring)\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
212 | 552 | RLx | (^|\W)history(\.[a-z]+)+\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
51 | 553 | RLx | (^|\W)(local|session)Storage\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
148 | 554 | RL | <svg/on | XSS | 12 | BODY|URL|ARGS|HEADERS |
200 | 555 | RLx | (^|\W)createElement\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
246 | 1000 | RLx | [^-:=\.\w\|]where[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
100 | 1001 | RLx | [^-:=\.\w\|]update[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
102 | 1002 | RLx | [^-:=\.\w\|]table[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
171 | 1003 | RLx | group[^-:=\.\w\|/]+by | SQLi | 2 | BODY|URL|ARGS|HEADERS |
92 | 1005 | RLx | order[^-:=\.\w\|]+by | SQLi | 3 | BODY|URL|ARGS|HEADERS |
146 | 1006 | RLx | [^-:=\.\w\|]limit[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
22 | 1007 | RLx | [^-:=\.\w\|]select[^-:=\.\w\|] | SQLi | 4 | BODY|URL|ARGS|HEADERS |
4 | 1008 | RLx | [^-:=\.\w\|]insert[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
211 | 1010 | RLx | [^-:=\.\w\|]truncate[^-:=\.\w\|] | SQLi | 3 | BODY|URL|ARGS|HEADERS |
202 | 1011 | RLx | (^|\W)benchmark\( | SQLi | 4 | BODY|URL|ARGS|HEADERS |
44 | 1012 | RLx | (^|\W)((var)?char|chr)\W*[(@]+[\d\s] | SQLi | 12 | BODY|URL|ARGS|HEADERS |
223 | 1016 | RLx | [^-:=\.\w\|]if[^-:=\.\w\|] | SQLi | 2 | BODY|URL|ARGS|HEADERS |
160 | 1021 | RLx | select[^-:=\.\w\|]{1,50}(.|\s){0,50}from | SQLi | 8 | BODY|URL|ARGS|HEADERS |
90 | 1023 | RL | extractvalue | SQLi | 4 | BODY|URL|ARGS|HEADERS |
82 | 1024 | RLx | (^|\W)concat\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
150 | 1025 | RL | updatexml | SQLi | 4 | BODY|URL|ARGS|HEADERS |
80 | 1026 | RLx | (^|\W)system\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
25 | 1027 | RLx | (^|\W)extractvalue\( | SQLi | 6 | BODY|URL|ARGS|HEADERS |
49 | 1028 | RLx | (^|\W)elt\( | SQLi | 6 | BODY|URL|ARGS|HEADERS |
232 | 1031 | RLx | (encode|decode)\W*[\(\)] | SQLi | 12 | BODY|URL|ARGS|HEADERS |
126 | 1032 | RL | group_concat | SQLi | 4 | BODY|URL|ARGS|HEADERS |
124 | 1033 | RLx | \Wrlike\( | SQLi | 6 | BODY|URL|ARGS|HEADERS |
109 | 1034 | RLx | [^-:=\.\w\|]database[^-:=\.\w\|] | SQLi | 4 | BODY|URL|ARGS|HEADERS |
160 | 1035 | RL | system_user | SQLi | 6 | BODY|URL|ARGS|HEADERS |
112 | 1036 | RL | version() | SQLi | 8 | BODY|URL|ARGS|HEADERS |
100 | 1037 | RLx | (^|\W)not\W+in\( | SQLi | 6 | BODY|URL|ARGS|HEADERS |
110 | 1038 | RLx | json(_\w+){1,2}\( | SQLi | 6 | BODY|URL|ARGS|Cookie |
93 | 1039 | RLx | [^-:=\.\w\|]contains[^-:=\.\w\|] | SQLi | 4 | BODY|URL|ARGS|HEADERS |
46 | 1040 | RLx | [^-:=\.\w\|]sleep[^-:=\.\w\|] | SQLi | 6 | BODY|URL|ARGS|HEADERS |
90 | 1042 | RL | table_name | SQLi | 6 | BODY|URL|ARGS |
79 | 1043 | RLx | \`\`\s*\`\` | SQLi | 2 | BODY|URL|ARGS |
243 | 1044 | RL | table.name | SQLi | 6 | BODY|URL|ARGS |
69 | 1045 | RL | isnull | SQLi | 2 | BODY|URL|ARGS|HEADERS |
245 | 1046 | RLx | _(en|de)crypt\( | SQLi | 6 | BODY|URL|ARGS|HEADERS |
34 | 1049 | RL | create_digest | SQLi | 6 | BODY|URL|ARGS|HEADERS |
53 | 1050 | RLx | log\d+\W*(\(|\)) | SQLi | 8 | URL|ARGS |
46 | 1053 | RLx | /(bin|sbin)/ | Other | 4 | BODY|URL|ARGS|HEADERS |
96 | 1055 | RL | to_base64 | SQLi | 6 | BODY|URL|ARGS|HEADERS |
239 | 1056 | RLx | [^-:=\.\w\|]replace[^-:=\.\w\|] | SQLi | 4 | BODY|URL|ARGS|HEADERS |
144 | 1057 | RL | master_pos_wait | SQLi | 8 | URL|ARGS |
225 | 1059 | RL | str_replace | SQLi | 8 | BODY|ARGS |
168 | 1060 | RL | user_meta | SQLi | 8 | BODY|URL|ARGS |
90 | 1061 | RL | regexp | SQLi | 2 | BODY|ARGS |
50 | 1063 | RLx | \d+[\'\`] | SQLi | 8 | URL |
164 | 1064 | RL | wp_comment | SQLi | 8 | BODY|URL|ARGS |
149 | 1065 | RL | wp_usermeta | SQLi | 8 | BODY|URL|ARGS |
7 | 1066 | RL | wp_post | SQLi | 8 | BODY|URL|ARGS |
233 | 1067 | RL | wp_term | SQLi | 8 | BODY|URL|ARGS |
138 | 1068 | RL | wp_user | SQLi | 8 | BODY|ARGS |
124 | 1069 | RL | wp_options | SQLi | 8 | BODY|ARGS |
131 | 1072 | RLx | (^|\W)print(_r|ln)?\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
17 | 1075 | RLx | \d\'\s*\w+=(\d+|\') | SQLi | 12 | URL|ARGS |
247 | 1077 | RLx | =(\-\w+|\w+[\'\)\"])(.|\s){0,30}\s+where\s+(.|\s){0,30}\s+(OR|AND) | SQLi | 12 | BODY|URL|ARGS|HEADERS |
223 | 1078 | RLx | ctx=web\&cache_filename=.+\.php.+IMresizedData=\<\?php | SQLi | 12 | BODY |
242 | 1081 | RLx | \w+=\d+\'($|\s) | SQLi | 12 | URL|ARGS |
242 | 1085 | RLx | \d+[\'\`] | SQLi | 2 | BODY|ARGS|HEADERS |
92 | 1086 | RLx | (\b(m(s(ysaccessobjects|ysaces|ysobjects|ysqueries|ysrelationships|ysaccessstorage|ysaccessxml|ysmodules|ysmodules2|db)|aster\.\.sysdatabases|ysql\.db)\b|s(ys(\.database_name|aux)\b|chema(\W*\(|_name\b)|qlite(_temp)?_master\b)|d(atabas|b_nam)e\W*\(|information_schema\b|pg_(catalog|toast)\b|northwind\b|tempdb\b)) | SQLi | 8 | BODY|URL|ARGS|HEADERS |
16 | 1087 | RLx | sleep\((\s*?)(\d*?)(\s*?)\)|benchmark\((.{0,50}?),(.{0,50}?)\) | SQLi | 12 | BODY|URL|ARGS|HEADERS |
184 | 1088 | RLx | (((select|;)\s+(benchmark|if|sleep)\s*?\(\s*?\(?\s*?\w+)) | SQLi | 12 | BODY|URL|ARGS|HEADERS |
154 | 1090 | RLx | ((alter\s*?\w+.{0,50}?(character|char)\s+set\s+\w+)|([\"'`];*?\s*?waitfor\s+(time|delay)\s+[\"'`])|([\"'`];.{0,50}\s*?\Wgoto\W)) | SQLi | 8 | BODY|URL|ARGS|HEADERS |
253 | 1091 | RLx | (^|\W)union(.|\s){1,50}select(.|\s){1,50}from\W | SQLi | 12 | BODY|URL|ARGS|HEADERS |
107 | 1092 | RLx | ((select\s*?pg_sleep)|(waitfor\s*?delay\s?[\"'`]+\s?\d)|(;\s*?shutdown\s*?(;|--|#|/\*|{))) | SQLi | 8 | BODY|URL|ARGS|HEADERS |
129 | 1093 | RLx | ["\[]\$(ne|eq|lte?|gte?|n?in|mod|all|size|exists|type|slice|x?or|div|like|between|and|where)["\]] | Injection | 12 | BODY|URL|ARGS|HEADERS |
92 | 1094 | RLx | ((procedure\s+analyse\s*?\()|(;\s*?(declare|open)\s+[\w-]+)|(create\s+(procedure|function)\s*?\w+\s*?\(\s*?\)\s*?-)|(declare[^\w]+[@#]\s*?\w+)|(exec\s*?\(\s*?@)) | SQLi | 8 | BODY|URL|ARGS|HEADERS |
243 | 1096 | RLx | xp_(servicecontrol|regread|regwrite|regdeletevalue|regdeletekey|fileexist|enumerrorlogs|readerrorlogs|enumdsn|enumgroups|ntsec_enumdomains) | SQLi | 12 | BODY|URL|ARGS|HEADERS |
163 | 1099 | RLx | (^|&)src=[^&]*?(http|ftp) | SQLi | 12 | URL |
240 | 1100 | RLx | [?&]home=[^&]*?(http|ftp) | Other | 12 | URL |
133 | 1102 | RLx | [?&]size=[^&]*?\x3b | SQLi | 12 | ARGS |
38 | 1104 | RL | action=getTopic | SQLi | 8 | BODY |
22 | 1105 | RLx | \[\#markup\]\=\S+\s+\S+ | RCE | 12 | BODY|URL|ARGS |
175 | 1107 | RL | found_rows | SQLi | 8 | URL|ARGS |
115 | 1108 | RL | tceles | SQLi | 4 | URL|ARGS|Cookie |
4 | 1109 | RLx | information(_|\.)schema | SQLi | 12 | BODY|URL|ARGS|HEADERS |
141 | 1110 | RLx | (\s|\+)(infile|outfile|dumpfile)(\s|\+) | SQLi | 8 | BODY|URL|ARGS|HEADERS |
165 | 1111 | RL | noinu | SQLi | 4 | URL|ARGS |
137 | 1112 | RL | substring% | SQLi | 8 | BODY|URL|ARGS|HEADERS |
109 | 1115 | RL | @@version | SQLi | 8 | BODY|URL|ARGS|HEADERS |
50 | 1116 | RL | schema | SQLi | 6 | URL|ARGS |
106 | 1117 | RL | datadir | SQLi | 8 | BODY|URL|ARGS|HEADERS |
119 | 1118 | RL | hostname | SQLi | 4 | BODY|URL|ARGS|HEADERS |
39 | 1119 | RL | rowcount | SQLi | 4 | BODY|URL|ARGS|HEADERS |
129 | 1120 | RLx | \s;\s | SQLi | 8 | URL|ARGS |
213 | 1121 | RL | coercibility | SQLi | 8 | URL|ARGS |
90 | 1123 | RL | COLLATION | SQLi | 8 | URL|ARGS |
239 | 1124 | RL | CONNECTION_ID | SQLi | 8 | URL|ARGS |
140 | 1125 | RL | current_user | SQLi | 4 | URL|ARGS |
210 | 1126 | RL | last_insert_id | SQLi | 8 | URL|ARGS |
210 | 1127 | RL | row_count | SQLi | 8 | URL|ARGS |
167 | 1128 | RL | session_user | SQLi | 8 | URL|ARGS |
64 | 1129 | RL | @user | SQLi | 8 | URL|ARGS |
253 | 1130 | RLx | /%?\*(.|\s){0,50}\*%?/ | SQLi | 6 | URL|ARGS |
48 | 1131 | RLx | /%?\*(.|\s){0,50}\*%?/ | SQLi | 2 | BODY |
217 | 1132 | RLx | ((/%?\*(.|\s){0,50}\*%?/)(.|\s){0,50}){3,} | SQLi | 12 | BODY|URL|ARGS|HEADERS |
238 | 1133 | RLx | name\[\d+.{20,}\] | SQLi | 12 | BODY |
97 | 1134 | RLx | admin(istrator)?'-- | SQLi | 12 | BODY|URL|ARGS|HEADERS |
176 | 1136 | RLx | ^(file|ftps?|https?)://(.{0,500})$ | SQLi | 8 | ARGS |
105 | 1137 | RLx | %0(.|\s){0,50}([a-z]%){3,} | SQLi | 12 | BODY|URL|ARGS|HEADERS |
103 | 1138 | RLx | (%\w%.{0,50}){5,} | SQLi | 8 | BODY|URL|ARGS|HEADERS |
11 | 1139 | RL | validate_password_strength | SQLi | 8 | URL|ARGS |
87 | 1141 | RL | libraryContent | SQLi | 8 | BODY |
8 | 1142 | RL | base64_decode | SQLi | 8 | BODY |
119 | 1143 | RL | globals[ | RCE | 8 | BODY|URL|ARGS |
193 | 1144 | RLx | (^|\W)response\.(write|flush|clear)\( | Injection | 12 | BODY|URL|ARGS|HEADERS |
226 | 1145 | RLx | \w=\/?\.{1,2}(\\|\/) | LFI | 8 | BODY|ARGS|Referer |
161 | 1311 | RL | <? | RCE | 4 | BODY |
129 | 1312 | RL | ?> | RCE | 4 | BODY |
113 | 1313 | RL | <?php | RCE | 12 | BODY|URL|ARGS|HEADERS |
94 | 1314 | RLx | \$_\w{1,15}\[ | Other | 12 | BODY|URL|ARGS|HEADERS |
209 | 1316 | RL | get_defined_functions | RCE | 12 | BODY|URL|ARGS|HEADERS |
1 | 1317 | RL | _PHPLIB[libdir] | Other | 8 | BODY|URL|ARGS|HEADERS |
86 | 1318 | RLx | auto_prepend_file|auto_append_file | RFI | 12 | URL|ARGS |
188 | 1322 | RL | burpcollaborator.net | Scanner | 12 | BODY|URL|ARGS|HEADERS |
196 | 1324 | RL | constructor.constructor | Other | 8 | BODY |
242 | 1352 | RL | XAttacker.php | Other | 12 | BODY|URL|ARGS |
204 | 1397 | RLx | include.?dir\x3D | Other | 12 | URL |
164 | 1398 | RLx | path=(https?|ftps?|php) | Other | 12 | URL |
239 | 1399 | RLx | php\?goto=(https?|ftps?|php) | RFI | 12 | URL |
62 | 1431 | RLx | /(admin/addcontent\.inc|images/psg)\.php | Other | 12 | URL |
51 | 1459 | RL | svg> | XSS | 3 | BODY |
14 | 1491 | RLx | [^-:\.\w\|]exec[^-:\.\w\|\/] | Injection | 8 | BODY|URL|ARGS|HEADERS |
25 | 1493 | RLx | (^|\W)die\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
207 | 1497 | RLx | (.{1,50}\(.{1,50}\)){3,} | Other | 12 | URL |
164 | 1500 | RLx | \.(.{0,250})~($|\s) | UWA | 12 | URL |
196 | 1501 | RLx | src=https?\x3a\x2f[^\x26\x20]*?(\x24\x28|%24%28) | UWA | 12 | URL|ARGS |
146 | 1502 | RL | .vscode | Other | 12 | URL |
39 | 1505 | RLx | \.(gemfile|gemfile|rb|irbrc)($|\s|\:) | UWA | 12 | URL |
122 | 1506 | RLx | \.(bzr|project|sublime(-workspace)?|md|svn|gitkeep|s3cfg|(git|hg|cvs)(ignore)?|subversion|csproj|(ftp)?config|cfg|atom|vb|vscode|circleci|npmrc)($|\s|\/|\:) | UWA | 12 | URL |
218 | 1512 | RLx | \.php[^3-7\/s][\w\-\_~]*(\.\w+)?$ | UWA | 12 | URL |
204 | 1513 | RLx | \.(py|pl|cgi)($|\s|\:) | UWA | 8 | URL |
45 | 1515 | RL | .ds_store | UWA | 12 | URL |
124 | 1516 | RLx | \.(jar|jsp|jspx|jspf|java|coffee|war|yml|cfm)($|\s|\:) | UWA | 12 | URL |
53 | 1517 | RLx | \.(conf|ssh|ini|inc|env|inc|viminfo|properties|dead\.letter|passwd|schema)($|\s|\:) | UWA | 8 | URL |
154 | 1518 | RLx | \.(phpinc|save|sav|swp|swo|lock|old|orig|log|tmp|temp|restore|suspected)($|\s|\:) | UWA | 12 | URL |
107 | 1519 | RLx | \.(bz2|gz|tar|xz|lzma)($|\s|\:) | UWA | 4 | URL |
168 | 1521 | RL | sftp-config.json | UWA | 12 | URL |
229 | 1522 | RL | .idea/ | UWA | 12 | URL |
145 | 1523 | RLx | ^/wp-content/plugins/($|\s) | UWA | 12 | URL |
84 | 1524 | RLx | /wp-content/plugins/.{1,50}/cache/ | UWA | 12 | URL |
54 | 1526 | RLx | \.(mdb|db|sqlite|sql)($|\s|\:) | UWA | 12 | URL |
219 | 1528 | RLx | id_(rsa|dsa)\.ppk($|\s|\:) | UWA | 12 | URL |
167 | 1559 | RLx | etc/(passwd|shadow) | UWA | 12 | BODY|URL|ARGS|HEADERS |
33 | 1560 | RLx | \W(win|system|php)\.ini | UWA | 8 | BODY|URL|ARGS|HEADERS |
136 | 1561 | RLx | \.(ksh|rsh|tcsh|csh|zsh|zshrc|bash|bash_profile|rksh|sh_history)($|\s|\:) | UWA | 12 | URL |
223 | 1562 | RLx | \.(bat|exe|dll|dat)($|\s|\:) | UWA | 12 | URL |
237 | 1808 | RL | composer.json | UWA | 8 | URL |
207 | 1811 | RLx | %psmodulepath%|%public%|%appdata%|%localappdata% | UWA | 12 | URL|ARGS |
96 | 1812 | RLx | %allusersprofile%|%userdata%|%username%|%userprofile% | UWA | 12 | URL|ARGS |
170 | 1813 | RLx | %homedrive%|%homepath% | UWA | 12 | URL|ARGS |
40 | 1814 | RLx | %homedrive%|%homepath% | UWA | 12 | URL|ARGS |
150 | 1816 | RLx | %systemdrive%|%systemroot%|%windir%|%comspec% | UWA | 12 | URL|ARGS |
116 | 1818 | RLx | %path%|%pathext% | UWA | 8 | URL|ARGS |
76 | 1819 | RLx | %computername%|%logonserver%|%prompt%|%userdomain% | UWA | 8 | URL|ARGS |
163 | 1820 | RL | db_details_importdocsql.php | UWA | 8 | URL |
205 | 1821 | RLx | /(global|dnewsweb|swsrv|ikonboard)\.cgi | UWA | 8 | URL |
48 | 1822 | RL | /math_sum.mscgi | UWA | 8 | URL|ARGS |
140 | 1823 | RLx | /(ksh|rsh|tcsh|csh|zsh|zshrc|bash|bash_profile|rksh)($|\s) | UWA | 12 | URL|ARGS |
23 | 1826 | RLx | \/(math_sum.mscgi|htsearch|printenv|db2www|document.d2w) | UWA | 12 | URL |
245 | 1827 | RL | /admentor/admin/admin.asp | UWA | 8 | URL |
39 | 1830 | RL | /timthumb.php | UWA | 4 | URL |
195 | 1831 | RL | /timthumbdir/cache | UWA | 4 | URL |
47 | 1832 | RL | /w3tc/dbcache | UWA | 8 | URL |
35 | 1834 | RL | php:// | UWA | 12 | BODY|URL|ARGS|HEADERS |
170 | 1835 | RL | ftp:// | UWA | 12 | BODY|ARGS |
135 | 1836 | RL | zlib:// | UWA | 12 | BODY|URL|ARGS|HEADERS |
157 | 1837 | RL | data:// | UWA | 12 | BODY|URL|ARGS|HEADERS |
137 | 1838 | RL | glob:// | UWA | 12 | BODY|URL|ARGS|HEADERS |
109 | 1839 | RL | phar:// | UWA | 12 | BODY|URL|ARGS|HEADERS |
208 | 1840 | RL | file:// | UWA | 12 | BODY|ARGS |
40 | 1841 | RL | /cfide/componentutils | UWA | 12 | URL |
204 | 1842 | RL | /mysqldumper | UWA | 12 | URL |
176 | 1843 | RLx | php(pg|my)admin | UWA | 12 | URL |
78 | 1845 | RL | /bin/sh | UWA | 12 | BODY|URL|ARGS|HEADERS |
37 | 1846 | RL | .htpasswd | UWA | 12 | URL|ARGS |
35 | 1847 | RL | .htaccess | UWA | 12 | URL|ARGS |
221 | 1848 | RL | whitelist.pac | UWA | 12 | URL |
57 | 1849 | RL | proxy.pac | UWA | 12 | URL |
42 | 1850 | RL | (?p=b)((?p=b)(?j:(?p<b>c)(?p<b>a(?p=b)))>wgxcredits) | UWA | 12 | BODY|ARGS|HEADERS |
5 | 1851 | RL | 0000::1 | UWA | 12 | X-Forward-For |
161 | 1852 | RL | 127.0.0 | UWA | 12 | X-Forward-For |
64 | 1853 | RL | (?j:(?|(:(?|(?'r')(\k'r')|((?'r')))h'rk'rf)|s(?'r')))) | UWA | 12 | HEADERS |
207 | 1854 | RL | /var/www/ | UWA | 12 | URL|ARGS |
155 | 1856 | RL | /philboard_admin.asp | UWA | 12 | URL|ARGS |
124 | 1857 | RL | /cgi-bin/ls | UWA | 8 | URL|ARGS |
41 | 1860 | RL | /wp-includes/rss-functions.php | UWA | 12 | URL |
23 | 1861 | RL | /wp-content/themes/RightNow/includes/uploadify/upload_settings_image.php | UWA | 12 | BODY |
212 | 1866 | RLx | stdin|stdout|stderr | UWA | 4 | BODY|URL|ARGS|HEADERS |
246 | 1868 | RL | X-Pingback-Forwarded-For: | UWA | 8 | X-Forward-For |
179 | 1869 | RLx | /dev/(tcp|udp) | UWA | 12 | BODY|ARGS|HEADERS |
126 | 1870 | RL | /sqlite/main.php | UWA | 12 | URL|ARGS |
11 | 1871 | RLx | (^|\W)php(_uname|credits|info|version)\( | Injection | 12 | BODY|URL|ARGS|HEADERS |
120 | 1872 | RLx | /~(root|ftp|nobody) | UWA | 12 | BODY|URL|ARGS |
20 | 1873 | RL | /htmlscript | UWA | 12 | URL |
219 | 1876 | RL | /post-query | UWA | 8 | URL |
176 | 1879 | RLx | [^/]https?:/ | UWA | 8 | URL |
181 | 1882 | RLx | (^|\W)javascript: | XSS | 8 | BODY|URL|ARGS|HEADERS |
253 | 1883 | RL | /DatabaseFunctions.php | UWA | 8 | URL |
195 | 1884 | RL | /GlobalFunctions.php | UWA | 8 | URL |
140 | 1885 | RL | /UpdateClasses.php | UWA | 8 | URL |
131 | 1886 | RL | /scripts/setup.php | UWA | 12 | URL |
203 | 1887 | RLx | (phpinfo|phpsysinfo)\.php | UWA | 12 | URL |
13 | 1888 | RL | /server_sync.php | UWA | 12 | URL |
183 | 1891 | RL | PageServices | UWA | 8 | URL|ARGS |
57 | 1892 | RL | /htgrep | UWA | 8 | URL |
204 | 1893 | RL | /WEB-INF/ | UWA | 12 | URL |
7 | 1894 | RL | /proc/self/ | UWA | 12 | BODY|URL|ARGS |
166 | 1895 | RL | phpb8b5f2a0-3c92-11d3-a3a9-4c7b08c10000 | UWA | 4 | ARGS |
18 | 1896 | RLx | phpe9568f3(4|5|6)-d428-11d2-a769-00aa001acf42 | UWA | 4 | ARGS |
46 | 1897 | RLx | /_vti_(adm|bin)/ | UWA | 12 | URL |
166 | 1898 | RL | /_vti_rpc | UWA | 12 | URL |
130 | 1899 | RL | /server-status | UWA | 12 | URL |
209 | 1900 | RL | /balancer-manager | UWA | 12 | URL |
95 | 1901 | RL | /host-manager/ | UWA | 12 | URL |
182 | 1902 | RL | fx29shcook | UWA | 8 | URL |
91 | 1903 | RLx | act=\S+&(d|f)= | UWA | 12 | BODY|ARGS |
179 | 1904 | RLx | act=(fxmailselfremove|encoder|eval|sql|phpinfo) | UWA | 12 | BODY|ARGS |
91 | 1905 | RLx | _act=(execute|list\s+files|upload) | UWA | 12 | BODY|ARGS |
54 | 1906 | RL | cmd_txt=1 | UWA | 8 | ARGS |
18 | 1907 | RL | c99.php | UWA | 12 | URL |
226 | 1908 | RLx | (\s|\+|#)cmd= | UWA | 12 | BODY|URL|ARGS|HEADERS |
247 | 1909 | RLx | c999sh_surl|c999shvars | UWA | 12 | Cookie |
159 | 1910 | RL | webconfig.txt.php | UWA | 12 | URL |
15 | 1911 | RL | wpad.dat | UWA | 12 | URL |
250 | 1913 | RL | composer.phar | UWA | 8 | URL |
202 | 1914 | RLx | adminer.*\.php | UWA | 12 | URL |
61 | 1915 | RLx | (wso|r57|r57shell)\.php | UWA | 12 | URL |
136 | 1917 | RL | /admin/templates/header.php | UWA | 8 | URL |
80 | 1918 | RL | /soapcaller.bs | UWA | 12 | URL |
185 | 1919 | RL | /plugin_googlemap2_proxy.php | UWA | 12 | URL |
70 | 1920 | RL | /images/stories/story.php | UWA | 12 | URL |
27 | 1921 | RLx | /plugins/system/.{1,50}\.php | UWA | 12 | URL |
143 | 1922 | RL | /.ssh/ | UWA | 12 | URL |
250 | 1923 | RL | /known_hosts | UWA | 12 | URL |
194 | 1924 | RL | /authorized_keys | UWA | 12 | URL |
9 | 1925 | RLx | \.(key|pem|id_rsa|id_dsa)($|\s) | UWA | 12 | URL |
52 | 1926 | RLx | \.(sh|bash|nano|irb|psql|mysql)_history($|\s) | UWA | 12 | URL |
179 | 1927 | RLx | \.(bac|bak|bkp|bkf|bkp|back|backup|bakup)($|\s) | UWA | 12 | URL |
221 | 1928 | RLx | \.(history|histfile)($|\s) | UWA | 12 | URL |
90 | 1929 | RL | proftpdpasswd | UWA | 12 | URL |
34 | 2100 | RLx | nessus|acunetix|nmap|sqlmap|[nw]ikto|dirbuster|gobuster|w3af|webster|openvas|meterpreter|network-services-auditor|wpscan|hydra|XSpider|Nuclei|l9explore | Scanner | 12 | User-agent |
53 | 2101 | RLx | absinthe|autogetcolumn|bsqlbf|cisco-torch|crimscanner|appscan_fingerprint|amiga-aweb|digimarc webreader | Scanner | 12 | User-agent |
109 | 2102 | RLx | sql\s+power\s+injector|dav\.pm|prog.customcrawler|whcc|grendel-scan|masscan | Scanner | 12 | User-agent |
172 | 2103 | RLx | shellshock-scan|thanks-rob|WebCruiser|webinspect|whisker|chinaclaw|whatweb|wordpress hash grabber | Scanner | 12 | User-agent |
191 | 2104 | RLx | mysqloit|netsparker|paros|pavuk|uil2pn|friendly-scanner|sundayddr|zmeu|sqlspider|Evasions | Scanner | 12 | User-agent |
195 | 2105 | RLx | apachebench|datacha0s|nv32ts|brutus|arachni|synapse|havij|sucuri|sitelock|scanalert | Scanner | 12 | User-agent |
32 | 2106 | RLx | http_get_vars|n-stealth|picscout|t34mh4k|webshag|mozilla/\d+\.\d+\s+sf | Scanner | 12 | User-agent |
6 | 2107 | RL | ++++++++result | Scanner | 12 | URL |
80 | 2112 | RL | /jmx-console/htmladaptor | Scanner | 12 | URL |
43 | 2115 | RLx | php/\d+\.|python-httplib|winhttprequest|pymills-spider/|^\. | Scanner | 1 | User-agent |
16 | 2116 | RL | internal dummy connection | Scanner | 12 | User-agent |
138 | 2400 | RL | base64 | Evasion | 2 | URL|ARGS |
119 | 2401 | RL | cghwaw5mbygpoyag | Evasion | 12 | BODY|URL|ARGS|HEADERS |
87 | 2402 | RL | http://http:// | Other | 12 | HEADERS |
19 | 2403 | RLx | boundary=\S+[,|;] | Evasion | 8 | Content-Type |
171 | 2404 | RL | mid% | Evasion | 8 | URL|ARGS |
115 | 2405 | RL | dual | Evasion | 2 | URL|ARGS |
138 | 2406 | RL | strcmp( | RCE | 8 | URL|ARGS |
252 | 2407 | RLx | (\\[0-7]{1,3}){3,} | Evasion | 8 | BODY|URL|ARGS|HEADERS |
200 | 2409 | RLx | &#\d+;? | Evasion | 0 | BODY|URL|ARGS|HEADERS|MLA |
248 | 2411 | RLx | (&#x[2-7]\w;(.|\s){0,50}){5,} | Evasion | 0 | BODY|URL|ARGS|HEADERS|MLA |
237 | 2413 | RLx | (file|ftps?|https?)://(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}) | Evasion | 12 | ARGS |
5 | 2414 | RLx | ((merge.{0,50}?using\s*?\()|(execute\s*?immediate\s*?[\"'`])|(match\s*?[\w(),+-]+\s*?against\s*?\()) | RCE | 8 | ARGS|Cookie |
158 | 2415 | RL | data:image | Evasion | 12 | URL |
139 | 2416 | RLx | (^|\W)(un)?hex\( | Evasion | 12 | BODY|URL|ARGS|HEADERS |
39 | 2700 | RL | .exec( | RCE | 12 | BODY|ARGS|Content-Type |
215 | 2702 | RL | /invoker/ejbinvokerservlet | Other | 12 | BODY|URL |
147 | 2703 | RL | service:wanipconnection: | Other | 12 | BODY |
95 | 2704 | RL | /struts2-blank/ | RCE | 12 | URL |
39 | 2705 | RLx | <[\s\+]*![\s\+]*(doctype|entity)[\s\+]+%*[\s\+]*[a-za-z1-9_-]*[\s\+]+system | Other | 12 | BODY |
105 | 2706 | RLx | multipart/form-data;\s*boundary=[a-zA-Z0-9_-]{4000,} | Other | 12 | Content-Type |
56 | 2707 | RL | java.beans.eventhandler | RCE | 12 | BODY|ARGS |
150 | 2708 | RL | java.lang. | RCE | 12 | BODY|ARGS |
58 | 2709 | RL | typo3_conf | Other | 12 | ARGS |
119 | 2711 | RLx | \(\s{0,50}\)\s{0,50}\{\s{0,50}\: | Other | 12 | BODY|ARGS|HEADERS |
45 | 2712 | RL | name[0%20 | Other | 12 | BODY |
129 | 2716 | RLx | script_fields.{0,50}import.{0,50}java\.util | RCE | 12 | BODY|ARGS |
65 | 2717 | RL | java.io. | RCE | 12 | BODY|ARGS |
49 | 2718 | RL | java.util. | RCE | 12 | BODY|ARGS |
225 | 2719 | RL | fill 'url | Other | 12 | BODY|URL|ARGS |
173 | 2720 | RL | $mft | Other | 8 | BODY|ARGS |
120 | 2721 | RLx | \.\./|php | Other | 12 | ARGS|$URL:/components/com_hdflvplayer/hdflvplayer/download.php |
176 | 2722 | RL | .ph | Other | 12 | $URL:/uploader/server/php/ |
147 | 2723 | RL | swp_url=http | Other | 12 | ARGS|$URL:/wp-admin/admin-post.php |
84 | 2725 | RL | system.listmethods | Other | 12 | $URL:/xmlrpc.php|BODY |
47 | 2726 | RL | system.getcapabilities | Other | 12 | $URL:/xmlrpc.php|BODY |
79 | 2727 | RL | pingback.ping | UWA | 12 | $URL:/xmlrpc.php|BODY |
31 | 2728 | RLx | ['"`)][\s\+]*(OR|AND|\|\||\&\&)(\s+NOT)?[\s\+]+(.{1,25})[\s\+]*([\!\<\>]?\=|\<|\>)[\s\+]*(.{1,25}) | SQLi | 12 | BODY|URL|ARGS|User-agent |
92 | 2729 | RLx | (^|\W)((var)?char|chr)\W*=\W*["'] | SQLi | 12 | BODY|URL|ARGS|HEADERS |
14 | 2730 | RLx | (^|\W)name_const\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
76 | 2731 | WL | %C0 | WL | 0 | Cookie |
166 | 2733 | RLx | \.([~-][\w]?|\$+)($|\s|\:) | UWA | 12 | URL |
109 | 2734 | RLx | \w=\/(etc|usr|var|bin|sbin|lib|lib64|run|sys|dev|root|home|opt|srv|mnt)\/ | Other | 12 | BODY|ARGS |
167 | 2735 | RLx | (^|\W)draggable(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
225 | 2736 | WLx | FBCR\/(\&\#\d+\-)+ | WL | 0 | User-agent |
135 | 2737 | RLx | filename\s*=\s*.+\.(php|pht|py|js\W|rb|pl|pm|cgi|aspx) | Other | 8 | Content-Disposition |
15 | 2738 | RLx | (^|\W)xbshell\W | Other | 12 | BODY|URL|ARGS|HEADERS |
197 | 2739 | RLx | (^|\W)union(\s|\+)+(all(\s|\+)+)?select\W | SQLi | 12 | BODY|URL|ARGS|HEADERS |
111 | 2740 | RL | deployment-config.json | UWA | 12 | URL |
247 | 2741 | RL | ftpsync.settings | UWA | 12 | URL |
220 | 2742 | RLx | (^|\W)convert\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
28 | 2743 | RLx | (^|\W)(md5|crc32|sha1|hash|crypt)\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
148 | 2744 | RLx | (^|\W)HashBytes\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
161 | 2745 | RLx | (^|\W)extractvalue\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
136 | 2746 | RLx | waitfor(\s|\+)+delay\W | SQLi | 12 | BODY|URL|ARGS|HEADERS |
119 | 2747 | RLx | img(\s|\+)*src=\"?(https?\:\/\/)?[\w|\.|\-|\/]+\.(txt|php|py|cgi|asp) | RFI | 12 | BODY |
29 | 2748 | RL | eval-stdin.php | UWA | 12 | URL |
131 | 2749 | RLx | \s(OR|\|\||AND|\&\&)(\s*not)?\s*(['")]\w*['"(]|\w*)\s*[!]?=\s*(['")]\w*['"(]|\w*)\s*\-\- | SQLi | 12 | BODY|URL|ARGS|User-agent |
23 | 2750 | RL | @pdiscoveryio | Scanner | 12 | User-agent |
151 | 2751 | RLx | (^|\W)function\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
85 | 2752 | RLx | (sql|old|bkp|bck|bckp|back|backup|archive)\.(zip|rar|7zip|bz2|gz|xz|lzma|tar|gz|tar\.gz)($|\s|\:) | UWA | 12 | URL |
10 | 2753 | RLx | (^|\W)includecomponent\( | RCE | 12 | BODY |
190 | 2754 | RLx | (^|\W)__schema\W*\{ | Other | 12 | BODY|ARGS |
190 | 2755 | RLx | \/\.\.[\;\+] | UWA | 12 | URL |
140 | 2756 | RLx | (^|\W)script[\s\+]+xmlns | XSS | 12 | BODY|URL|ARGS|HEADERS |
33 | 2757 | RLx | (^|\W)tostring\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
20 | 2758 | RLx | (^|\W)shell_exec\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
131 | 2759 | RLx | \=[\s\+]*\$\{\w+[\+\-\*\/]\w+\} | RCE | 12 | BODY|ARGS |
233 | 2760 | RLx | (^|\W)nslookup\W | RCE | 12 | BODY|URL|ARGS|HEADERS |
211 | 2761 | RLx | \|[\s\+]*([\/]*(\w|\.)+[\/]+)?(bash|perl|python|php)\W | RCE | 8 | BODY|URL|ARGS|HEADERS |
235 | 2762 | RLx | (^|\W)gethostbyname\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
169 | 2763 | RLx | ['"`)][\s\+]*(OR|AND|\|\||\&\&)(\s+NOT)?[\s\+\"\'\(\)]+(.{1,25})[\s\+\"\'\(\)]+([\!\<\>]?\=|\<|\>)[\s\+\"\'\(\)]+(.{1,25}) | SQLi | 12 | BODY|URL|ARGS|User-agent |
51 | 2764 | WLx | \w\-\-\w | WL | 0 | BODY|URL|ARGS|HEADERS |
225 | 2766 | RLx | bxss\W*\.me | Scanner | 12 | BODY|URL|ARGS|HEADERS |
151 | 2767 | RL | sysdate( | Injection | 12 | BODY|URL|ARGS|HEADERS |
70 | 2768 | RLx | on(waiting|pause|show|start|end|unload|drop|submit|close|after(print|scriptexecute)|contextmenu|cellchange)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
224 | 2769 | RLx | on(cuechange|(de)?activate|finish|fullscreenchange|hashchange|invalid|message|repeat)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
60 | 2770 | RLx | on(resize|scroll|search|seeked|seeking|timeupdate|touchend|touchmove|touchstart|volumechange)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
236 | 2771 | RLx | on(mozfullscreenchange|pagehide|pageshow|popstate|progress|readystatechange|transitioncancel|transitionrun|transitionstart|unhandledrejection)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
189 | 2772 | RLx | onwebkitanimation(end|iteration|start|end)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
91 | 2773 | RLx | onbefore((de)?activate|copy|cut|editfocus|paste|update|scriptexecute|input)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
43 | 2774 | RLx | onpointer(down|enter|leave|move|out|over|rawupdate|up)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
67 | 2775 | RLx | onanimation(cancel|iteration|start|end)(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
113 | 2776 | RLx | (^|\W)strrev\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
118 | 2777 | RLx | (djy|qpy)l18\.com | Other | 12 | ARGS |
204 | 2778 | RLx | (^|\W)execute\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
168 | 2779 | RLx | (^|\W)(atob|btoa)\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
82 | 2780 | RL | Fuzz Faster | Scanner | 12 | User-agent |
142 | 2781 | RLx | (^|\W)get(Runtime|Response|Writer|Property|InputStream)\( | RCE | 12 | BODY|Content-Type |
134 | 2782 | RL | .start( | RCE | 12 | BODY|Content-Type |
61 | 2783 | RL | X-Scanner: Netsparker | Scanner | 12 | X-Scanner |
191 | 2784 | RL | codepoints-to-string( | Injection | 12 | BODY|URL|ARGS|HEADERS |
147 | 2785 | RLx | (^|\W)substring\( | Injection | 8 | BODY|URL|ARGS|HEADERS |
139 | 2786 | RL | string-length( | Injection | 12 | BODY|URL|ARGS|HEADERS |
177 | 2787 | RLx | (^|\W)starts-with\( | Injection | 12 | BODY|URL|ARGS|HEADERS |
56 | 2788 | RLx | (^|\W)contains\( | Injection | 8 | BODY|URL|ARGS|HEADERS |
140 | 2789 | RL | db.collection.find( | Injection | 12 | BODY|URL|ARGS|HEADERS |
170 | 2790 | RLx | (^|\W)match\( | Injection | 8 | BODY|URL|ARGS|HEADERS |
131 | 2791 | RLx | (^|\W)document\[('|"|`)\w+('|"|`)\] | XSS | 12 | BODY|URL|ARGS|HEADERS |
63 | 2792 | RL | knoxss.me | Scanner | 12 | BODY|URL|ARGS|HEADERS |
180 | 2793 | RLx | (^|\W)confirm(\.call)?\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
229 | 2794 | RLx | (^|\W)array\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
157 | 2795 | RL | array_map( | Injection | 12 | BODY|URL|ARGS|HEADERS |
35 | 2796 | RL | base_convert( | Injection | 12 | BODY|URL|ARGS|HEADERS |
161 | 2797 | RL | scaninfo@expanseinc.com | Scanner | 12 | User-agent |
183 | 2798 | RL | .xss.ht | Scanner | 12 | BODY|URL|ARGS|HEADERS |
43 | 2799 | RLx | =\$\{\d+[+\-*%]\d+\} | Injection | 8 | BODY|ARGS |
165 | 2800 | RL | load_file( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
103 | 2801 | RLx | (^|\W)start-sleep[\s\+]+\- | RCE | 12 | BODY|URL|ARGS|HEADERS |
74 | 2802 | RLx | (^|\W)passthru\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
162 | 2803 | RLx | (^|\W)sleep\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
164 | 2804 | RLx | (^|\W)typeof\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
244 | 2805 | RLx | \Wisfinite\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
24 | 2806 | RLx | (^|\W)sleep[\s\+]+\d | Injection | 8 | BODY|URL|ARGS|HEADERS |
65 | 2807 | RLx | (^|\W)prompt(\.call)?[(,`] | XSS | 8 | BODY|URL|ARGS|HEADERS |
112 | 2808 | RLx | (^|\W)substr\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
47 | 2809 | RLx | (^|\W)ord\( | Injection | 8 | BODY|URL|ARGS|HEADERS |
146 | 2810 | RLx | (^|\W)mid\( | SQLi | 8 | BODY|URL|ARGS|HEADERS |
25 | 2811 | RLx | (^|\W)ifnull\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
178 | 2812 | RLx | (^|\W)cast\( | SQLi | 8 | BODY|URL|ARGS|HEADERS |
33 | 2813 | RLx | (^|\W)database\( | SQLi | 8 | BODY|URL|ARGS|HEADERS |
82 | 2814 | RL | scaninfo@paloaltonetworks.com | Scanner | 12 | User-agent |
112 | 2815 | RLx | (^|\W)require\( | Injection | 8 | BODY|URL|ARGS|HEADERS |
71 | 2816 | RLx | (^|\W)endianness\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
208 | 2817 | RL | charCodeAt( | XSS | 12 | BODY|URL|ARGS|HEADERS |
13 | 2818 | RLx | (^|\W)fillrect\( | XSS | 12 | BODY|URL|ARGS|HEADERS |
119 | 2819 | RL | fromcharcode( | XSS | 12 | BODY|URL|ARGS|HEADERS |
180 | 2820 | RLx | @Grab(Config|Resolver)?\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
79 | 2821 | RLx | (^|\W)r87\.(com|me)\W | Scanner | 12 | BODY|URL|ARGS|HEADERS |
245 | 2822 | RLx | (^|\W)echo(\s|\+)+\$\( | OSCI | 8 | BODY|URL|ARGS|HEADERS |
181 | 2823 | RLx | (^|\W)echo(\s|\+)+(\-\w+(\s|\+)+)?[\'\"\`] | OSCI | 8 | BODY|URL|ARGS|HEADERS |
233 | 2824 | RLx | (database|db|dump)\.tar(\.gz)?($|\s|\:) | UWA | 12 | URL |
124 | 2826 | RLx | (^|\W)alert\.name\W | XSS | 12 | BODY|URL|ARGS|HEADERS |
142 | 2827 | RL | .newInstance( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
98 | 2828 | RL | .forName( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
123 | 2829 | RLx | config\.inc(\.(bz2|gz|xz|tar(\.(bz2|gz|lzma|xz))?))?($|\s|\:) | UWA | 12 | URL |
248 | 2830 | RLx | config\.(bz2|gz|xz|tar(\.(bz2|gz|lzma|xz))?)($|\s|\:) | UWA | 12 | URL |
28 | 2831 | WL | Open BSD | WL | 0 | User-agent |
14 | 2832 | RLx | (^|\W)db.bz2($|\s|\:) | UWA | 12 | URL |
93 | 2833 | RL | config_db.php | UWA | 12 | URL |
29 | 2834 | RLx | (^|\W)cat_code\W | SQLi | 8 | BODY|URL|ARGS|HEADERS |
158 | 2835 | RL | x-wvs-id | Scanner | 12 | HEADERS |
8 | 2836 | RLx | (^|\W)(un)?escape\W | XSS | 6 | BODY|URL|ARGS|HEADERS |
245 | 2837 | WLx | \$\{(ad_id|platform|campaign_id)\} | WL | 0 | BODY|ARGS|HEADERS |
46 | 2838 | RLx | (^|\W)updatexml\( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
229 | 2839 | RLx | (^|\W)valueOf\W*(\(|\'|\"|.) | XSS | 8 | BODY|URL|ARGS|HEADERS |
152 | 2840 | RL | JSON.stringify( | XSS | 8 | BODY|URL|ARGS|HEADERS |
117 | 2841 | RLx | (^|\W)window\.[a-z] | XSS | 4 | BODY|URL|ARGS|HEADERS |
214 | 2842 | RLx | (^|\W)(global|window)eventhandlers\.[a-z] | XSS | 8 | BODY|URL|ARGS|HEADERS |
111 | 2843 | RLx | (^|\W)globalthis\W | XSS | 6 | BODY|URL|ARGS|HEADERS |
191 | 2844 | RLx | (^|\W)fopen\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
144 | 2845 | RLx | (^|\W)f(write|puts)\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
82 | 2846 | RLx | (^|\W)printenv\W | OSCI | 8 | BODY|URL|ARGS|HEADERS |
100 | 2847 | WL | gpg.key | WL | 0 | URL |
194 | 2848 | RLx | (^|\W)ini_set\( | RCE | 12 | BODY|URL|ARGS|HEADERS |
199 | 2849 | RL | set_time_limit( | RCE | 12 | BODY|URL|ARGS|HEADERS |
249 | 2850 | RLx | (^|\W)isset\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
18 | 2851 | RL | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | UWA | 12 | URL |
15 | 2852 | RL | .interact.sh | Scanner | 12 | BODY|URL|ARGS|HEADERS |
251 | 2853 | RL | reflect.apply( | XSS | 8 | BODY|URL|ARGS|HEADERS |
111 | 2854 | RL | promise.all( | XSS | 8 | BODY|URL|ARGS|HEADERS |
64 | 2855 | RL | .then(alert | XSS | 8 | BODY|URL|ARGS|HEADERS |
175 | 2856 | RL | /backup/ | UWA | 12 | URL |
93 | 2857 | RL | 0x00 | Evasion | 4 | BODY|URL|ARGS|HEADERS |
116 | 2858 | RL | string.fromcodepoint( | XSS | 12 | BODY|URL|ARGS|HEADERS |
149 | 2859 | RL | .tolowercase( | XSS | 8 | BODY|URL|ARGS|HEADERS |
70 | 2860 | RL | netsystemsresearch.com | Scanner | 12 | User-agent |
123 | 2861 | RL | internet-structure-research-project-bot | Scanner | 12 | User-agent |
226 | 2862 | RL | /config.bak.php | UWA | 12 | URL |
133 | 2863 | RL | anonymousfox.co | Scanner | 12 | Referer |
178 | 2864 | RL | system.multicall | Other | 12 | BODY|$URL:/xmlrpc.php |
49 | 2865 | RLx | \/wp-config\.(orig|txt|php[._](bak|old|new)) | UWA | 12 | URL |
130 | 2866 | RLx | jndi\:(dns|rmi|iiop|ldap)\:\/\/ | RCE | 12 | BODY|URL|ARGS|HEADERS |
62 | 2867 | RLx | \$\{(lower|upper)\: | RCE | 8 | BODY|URL|ARGS|HEADERS |
85 | 2868 | RLx | \$[\\]?\{\:\:\-[jndilaprmso][\\]?\} | RCE | 8 | BODY|URL|ARGS|HEADERS |
10 | 2869 | RLx | \$[\\]?\{env\:ENV_NAME\:\-[jndilaprmso][\\]?\} | RCE | 8 | BODY|URL|ARGS|HEADERS |
78 | 2870 | RL | str_pad( | RCE | 8 | BODY|URL|ARGS|HEADERS |
40 | 2871 | RL | mysqli:: | RCE | 8 | BODY|URL|ARGS|HEADERS |
200 | 2872 | RL | /.aws/credentials | UWA | 12 | URL |
186 | 2873 | RLx | \.pydevproject($|\s|\:) | UWA | 12 | URL |
223 | 2874 | RL | BluechipBacklinks | Scanner | 12 | User-agent |
150 | 2875 | RL | rookee.bot | Scanner | 12 | User-agent |
75 | 2876 | RLx | (alfa_data|alfacgiapi|cgialfa)\/.{0,50}\.alfa($|\s|\/|\:) | UWA | 12 | URL |
244 | 2877 | RL | .httpservletresponse | RCE | 8 | BODY|Content-Type |
100 | 2878 | RLx | \/(db|backup|config)\d*\.(bz2|gz|tar|xz|lzma)($|\s|\:) | UWA | 8 | URL |
5 | 2879 | RLx | (^|\W)var_dump\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
247 | 2880 | RL | wp_is_mobile | Scanner | 12 | User-agent |
60 | 2881 | RL | PHP/{5|6|7} | Scanner | 12 | User-agent |
43 | 2882 | RL | class.classloader.resources.dircontext.docbase | RCE | 8 | ARGS |
128 | 2883 | RL | github.com/gocolly | Scanner | 12 | User-agent |
123 | 2884 | RL | .get_host_address( | SQLi | 12 | BODY|URL|ARGS|HEADERS |
68 | 2885 | RLx | CensysInspect|censys\.io | Scanner | 12 | User-agent |
181 | 2886 | RLx | \.(git|svn) | UWA | 8 | URL |
76 | 2887 | RL | .touppercase( | XSS | 8 | BODY|URL|ARGS|HEADERS |
4 | 2888 | RL | 0x[] | RCE | 8 | BODY |
15 | 2889 | RL | 0x[]=androxgh0st | RCE | 12 | BODY |
32 | 2890 | RLx | while\s*\( | RCE | 4 | BODY|URL|ARGS|HEADERS |
59 | 2891 | RL | .equals( | RCE | 4 | BODY|URL|ARGS|HEADERS |
13 | 2892 | RL | class.module.classLoader | RCE | 12 | BODY|URL|ARGS|HEADERS |
191 | 2893 | RL | .getInputStream( | RCE | 8 | BODY|URL|ARGS|HEADERS |
131 | 2894 | RL | .getRuntime( | RCE | 8 | BODY|URL|ARGS|HEADERS |
14 | 2895 | RL | .getParameter( | RCE | 8 | BODY|URL|ARGS|HEADERS |
45 | 2896 | RLx | \.queryselector(all)?\( | XSS | 8 | BODY|URL|ARGS|HEADERS |
157 | 2897 | RL | springframework.context.support.FileSystemXmlApplicationContext | RCE | 8 | BODY|URL|ARGS|HEADERS |
37 | 2898 | RLx | reflect\.(apply|cons|def|del|get|has|isext|own|prev|set) | XSS | 4 | BODY|URL|ARGS|HEADERS |
177 | 2899 | RL | sort.call | XSS | 2 | BODY|URL|ARGS|HEADERS |
76 | 2900 | RL | eval.apply | XSS | 4 | BODY|URL|ARGS|HEADERS |
81 | 2901 | RL | .surf.ias-lab.de | Scanner | 12 | ARGS |
172 | 2902 | RL | .shift() | XSS | 2 | BODY|URL|ARGS|HEADERS |
74 | 2903 | RL | .with( | XSS | 2 | BODY|URL|ARGS|HEADERS |
167 | 2904 | RL | __class__ | RCE | 4 | BODY|ARGS|HEADERS |
32 | 2905 | RLx | (^|\W)(wget|curl)\W | RCE | 2 | BODY|ARGS|Referer |
155 | 2906 | RLx | (^|\W)alert\W | XSS | 4 | BODY|URL|ARGS|HEADERS |
150 | 2907 | RL | .getResource( | RCE | 8 | BODY|URL|ARGS|HEADERS |
126 | 2908 | RLx | \{\s*php\s*\} | RCE | 4 | BODY|URL|ARGS|HEADERS |
91 | 2909 | RL | freemarker.template.utility.execute | RCE | 8 | BODY |
161 | 2910 | RLx | (^|\W)window\[ | XSS | 4 | BODY|URL|ARGS|HEADERS |
144 | 2911 | RL | MakeViewVariableOptionalSolution | RCE | 12 | BODY |
145 | 2912 | RLx | (^|\W)attr\( | XSS | 2 | BODY|URL|ARGS|HEADERS |
151 | 2913 | RL | @( | Injection | 2 | BODY|URL|ARGS|HEADERS |
159 | 2914 | RL | {$ | Injection | 2 | BODY|URL|ARGS|HEADERS |
140 | 2915 | RLx | :[\/\\]+windows[\/\\]+ | UWA | 8 | BODY|URL|ARGS|HEADERS |
83 | 2917 | RLx | ['"][\s+]*;[\s+]*return[\s+] | Injection | 4 | BODY|URL|ARGS|HEADERS |
80 | 2918 | RLx | ;[\s+]*([\/]([usrbinloca?]{3,5}[\/]){1,4})?([cat?]{3,3}|[les?]{4,4})[\s+]+[\/]?\w+ | Evasion | 2 | BODY|URL|ARGS|HEADERS |
194 | 2919 | RLx | echo[\s+]+var | Injection | 4 | BODY|URL|ARGS|HEADERS |
126 | 2920 | RLx | exec[\s+]+cmd | Injection | 4 | BODY|URL|ARGS|HEADERS |
212 | 2921 | RLx | (^|\W)location\.(ancestor|href|protocol|host|pathname|search|hash|origin) | XSS | 12 | BODY|URL|ARGS|HEADERS |
132 | 2922 | RL | <%= | Injection | 4 | BODY|URL|ARGS|HEADERS |
146 | 2923 | RLx | top\[.{1,50}\]\( | XSS | 8 | BODY|URL|ARGS|HEADERS |
99 | 2924 | RL | .map( | XSS | 4 | BODY|URL|ARGS|HEADERS |
86 | 2925 | RLx | &([lr]par|quot|apos|grave|tab|nbsp); | Evasion | 0 | BODY|URL|ARGS|HEADERS|MLA |
38 | 2926 | RLx | \/(etc|usr|var|bin|sbin)\/ | UWA | 2 | BODY|URL|ARGS|HEADERS |
85 | 2927 | RL | #{ | Injection | 2 | BODY|URL|ARGS |
15 | 2928 | RLx | \{\{[_]*self.*\}\} | Injection | 8 | BODY|URL|ARGS|HEADERS |
207 | 2929 | RLx | ondata(available|setchanged|setcomplete)?(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
169 | 2930 | RLx | ondrag(end|enter|leave|start|over)?(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
115 | 2931 | RLx | onmove(end|start)?(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
229 | 2932 | RLx | onrow(enter|exit|s(delete|inserted))(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
80 | 2933 | RLx | on(load(start|eddata)?|focus(in|out)?|key(down|press|up)|pointer(over|enter|down|move|up|cancel|out|leave))(\s|\+)*\= | XSS | 12 | BODY|URL|ARGS|HEADERS |
139 | 2934 | RL | dict:// | UWA | 8 | BODY|ARGS |
224 | 2935 | RL | sftp:// | UWA | 8 | BODY|ARGS |
62 | 2936 | RL | tftp:// | UWA | 8 | BODY|ARGS |
223 | 2937 | RL | ldap:// | UWA | 8 | BODY|ARGS |
187 | 2938 | RL | gopher:// | UWA | 8 | BODY|ARGS |
137 | 2939 | RL | netdoc:// | UWA | 8 | BODY|ARGS |
152 | 2940 | RLx | \$(ne|eq|lte?|gte?|n?in|mod|all|size|exists|type|slice|x?or|div|like|between|and|where): | Injection | 4 | BODY|URL|ARGS|HEADERS |
207 | 2941 | RL | db.injection.insert( | Injection | 12 | BODY|URL|ARGS|HEADERS |
181 | 2942 | RLx | \.oast\.(me|pro) | Scanner | 12 | BODY|URL|ARGS|HEADERS |
94 | 2943 | RL | *{ | Injection | 2 | BODY|URL|ARGS |
131 | 2944 | RL | BugBountyBot | Scanner | 12 | User-agent |
8 | 2945 | RLx | \$0\s*<<<\s*\$ | Evasion | 8 | BODY|URL|ARGS|HEADERS |
199 | 2946 | RL | console.log( | XSS | 8 | BODY|URL|ARGS|HEADERS |
210 | 2947 | RL | navigation.onnavigate | XSS | 8 | BODY|URL|ARGS|HEADERS |
200 | 2948 | RL | document.queryselector( | XSS | 8 | BODY|URL|ARGS|HEADERS |
44 | 2949 | RL | .setAttribute( | XSS | 8 | BODY|URL|ARGS|HEADERS |
200 | 2950 | RL | json_depth( | SQLi | 8 | BODY|URL|ARGS|HEADERS |
215 | 2951 | RLx | (^|\W)printf\W | OSCI | 8 | BODY|URL|ARGS|HEADERS |
120 | 2952 | RL | x-web-scanner-info | Scanner | 8 | HEADERS |
3 | 2953 | RL | /(s(x)) | UWA | 2 | URL |
243 | 2954 | RLx | \|\s*set\s | OSCI | 8 | BODY|URL|ARGS|HEADERS |
247 | 2955 | RLx | [^-:=\.\w\|]json_(array|contains_path|depth|extract|keys|length|object|quote|search|type|unquote|valid)[^-:=\.\w\|] | SQLi | 4 | BODY|URL|ARGS|HEADERS |
80 | 2956 | RL | `id` | OSCI | 4 | BODY|URL|ARGS|HEADERS |
218 | 2957 | RL | curl_setopt( | RCE | 8 | BODY|URL|ARGS|HEADERS |
139 | 2958 | RLx | (^|\W)stristr\( | RCE | 8 | BODY|URL|ARGS|HEADERS |
5 | 2959 | RL | file_get_contents( | RCE | 8 | BODY|URL|ARGS|HEADERS |
86 | 2960 | RLx | \$_(GET|POST|FILES)\[ | RCE | 8 | BODY|URL|ARGS|HEADERS |
143 | 2961 | RL | g=echo Sp3ctra; | UWA | 12 | Cookie |
98 | 2962 | RLx | {{\s*(\d+|'\d+')\s*[*+]\s*(\d+|'\d+')?\s*}} | Injection | 8 | BODY|URL|ARGS |
103 | 2963 | RLx | {{\s*\d+\s*\|add:\s*\d+\s*}} | Injection | 8 | BODY|URL|ARGS |
122 | 2964 | RLx | (^|\W)import\( | XSS | 8 | BODY|URL|ARGS|HEADERS |