Skip to content

SQLi and XSS payloads in filenames

Examples

  • SQLi payloads in file name: FileName'+AND+sleep(10)--+-.txt
  • XSS payloads in file name: FileName'><svg/onload=alert()>.txt