Skip to content
Syslifters Handbook
Search
K
Main Navigation
Home
Pentesting Manual
Organization
Blog
English
Deutsch
English
Deutsch
Appearance
EN
Menu
Return to top
On this page
Are you an LLM? You can read better optimized documentation at /pentesting-manual/web-applications/file-upload/sqli-xss-in-filename.md for this page in Markdown format
SQLi and XSS payloads in filenames
Examples
SQLi payloads in file name:
FileName'+AND+sleep(10)--+-.txt
XSS payloads in file name:
FileName'><svg/onload=alert()>.txt