/netcore_get.cgi
/cgi-bin/luci/er/vlanTag=pwd
/cgi-bin/luci/er/verify_wifi?wifi_conflict=pwd
/cgi-bin/luci/er/get_syslog
/cgi/confup
/web/entry/es/address/adrsGetUser.cgi
/web/entry/es/address/adrsList.cgi
/web/entry/es/address/adrsSetUser.cgi
/mt/mt.cgi
/if.cgi
/cgi-bin/libagent.cgi
/reboot.cgi
/cgi-bin/web.cgi
/cgi-bin/onvif.cgi
/cgi-bin/websrunnings.cgi
/mnt_ping.cgi
/cgi-bin/adsl_init.cgi
/cgi-bin/chkwifi.cgi
/cgi-bin/ddns_start.cgi
/cgi-bin/getadslattr.cgi
/cgi-bin/getddnsattr.cgi
/cgi-bin/getinetattr.cgi
/cgi-bin/getinterip.cgi
/cgi-bin/getnettype.cgi
/cgi-bin/getupnp.cgi
/cgi-bin/getwifi.cgi
/cgi-bin/getwifiattr.cgi
/cgi-bin/ptzctrldown.cgi
/cgi-bin/ptzctrlleft.cgi
/cgi-bin/ptzctrlright.cgi
/cgi-bin/ptzctrlup.cgi
/cgi-bin/ptzctrlzoomin.cgi
/cgi-bin/ptzctrlzoomout.cgi
/cgi-bin/ser.cgi
/cgi-bin/setadslattr.cgi
/cgi-bin/setddnsattr.cgi
/cgi-bin/setinetattr.cgi
/cgi-bin/setwifiattr.cgi
/cgi-bin/testwifi.cgi
/cgi-bin/upnp_start.cgi
/cgi-bin/upnp_stop.cgi
/cgi-bin/wifi_start.cgi
/cgi-bin/wifi_stop.cgi
/dana-na/auth/url_admin/login.cgi
/dana-admin/diag/diag.cgi
/dana-na/auth/setcookie.cgi
/cgi-bin/protected/manage_files.cgi
/cgi-bin/protected/discover_and_manage.cgi?action=snmp_browser&hst_id=none&snmpv3_profile_id=&ip_address=
/cgi-bin/protected/manage_hosts_short.cgi?action=search_proceed&search_pattern=
/cgi-bin/animate.cgi
/mobile_viewer_login.html
/cgi-bin/cgiServer.exx?command=dumpConfigFile(/etc/shadow)
/password_change.cgi
/setup.cgi
/sysinfo.cgi
/proc/index_tree.cgi
/sdwan/nitro/v1/config/get_package_file?action=file_download
/cgi-bin/installpatch.cgi?swc-token=%d&installfile=
/_s_/dyn/pro/EditorUI_saveScript
/xymon-seccgi/
/admin.cgi?action=config_restore
/admin.cgi?action=config_save
/admin.cgi?action=upgrade
/cgi-bin/file_transfer.cgi
/cgi-bin/webctrl.cgi?action=pingtest_update&ping_addr=127.0.0.1
/cgi-bin/webctrl.cgi
/cgi-bin/smap
/userLogin.cgi
/cgi-bin/pfdisplay.cgi
/sysinfo.cgi?xnavigation=1
/proc/index_tree.cgi
/updown/upload.cgi
/file/show.cgi
/session_login.cgi
/cgi-bin/qcmap_auth
/cgi-bin/qcmap_web_cgi
/1search.cgi
/BRS_netgear_success.html
/BUx8nLlIMxI
/BlockSite.asp
/BlockTime.asp
/CGI-BIN/WCONSOLE.DLL
/CGI-Bin/frame.html
/Configuration_file.cfg
/Contents/exportLogs.asp
/DIRTOECART/index.cgi
/Details.cfm
/DetectionPolicy/rules/rulesimport.cgi
/DocController
/EDCstore.pl
/GWExtranet/scp.dll
/GWExtranet/scp.dll/frmonth
/NeT/alpha.txt
/PUBLIC/ADMIN/INDEX.HTM
/PWD_password.htm
/Pages/product.aspx
/ROADS/cgi-bin/search.pl
/Results.cfm
/SCRIPTS/WA-MSD.EXE
/SCRIPTS/WA-USIAINFO.EXE
/SCRIPTS/WA.EXE
/Scripts/wa-demo.exe
/Sdocument702.html
/ShowAlbum
/ShowGraphic
/ShowVideo
/TR/2000/CR-SVG-20001102/DTD/svg-20001102.dtd
/Translators/
/UNCWS/Management.asmx
/Unsecured.cgi
/UnsecuredEnable.cgi
/WEBACCOUNT.CGI                                    
/WebAdmin.dll
/WebAdmin/modalframe.wdm
/WebAdmin/useredit_account.wdm
/WebGUI/index.pl/homels
/WebID/IISWebAgentIF.dll
/YaBB.pl
/ZendServer/Code-Tracing/Generate-Dump
/ZendServer/Configuration/Webserver-Restart
/ZendServer/Directives/Save/extension/WmVuZCBEZWJ1Z2dlcg%3D%3D
/ZendServer/Directives/Save/extension/WmVuZCBKYXZhIEJyaWRnZQ%3D%3D
/ZendServer/Directives/Save/extension/WmVuZCBPcHRpbWl6ZXIr
/ZendServer/Job-Queue-Scheduling/Save-Rule
/ZendServer/Page-Cache/Save-Rule
/_vti_bin/_vti_adm/fpadmdll.dll
/ad.cgi
/adcenter.cgi
/add_acl
/addlink_lwp.cgi
/admdat/admin.dat
/admin.cgi
/admin.pl
/admin/index.pl
/admin/restartMessage.shtml
/admin/setgen/security.shtml
/admin/user.pl
/admin/user/user.cgi
/admin/wg_user-info.ml
/aktivate/cgi-bin/catgy.cgi
/api/backup/version.cgi
/apply.cgi
/apply2.cgi
/apply_noauth.cgi
/apps/web/global.fcgi
/apps/web/index.fcgi
/apps/web/vs_diag.cgi
/as_web.exe
/as_web4.exe
/asterisk/contact_chooser.cgi
/asterisk/contacts.cgi
/at/create_job.cgi
/atl.cgi
/auction.pl
/auth.cgi
/auth.html
/awcuser/cgi-bin/vcs
/awstats.pl
/awstats/awstats.pl
/axis-cgi/admin/pwdgrp.cgi
/axis-cgi/admin/restart.cgi
/axis-cgi/buffer/command.cgi
/axis-cgi/io/virtualinput.cgi
/axoverzicht.cgi
/backup/
/bandwidth/index.cgi
/banners.cgi
/bb/logs/evil.php3.
/bin/common/addressbook.pl
/bin/common/announcement.pl
/bin/common/calendar.pl
/bin/common/search.pl
/bin/common/tasks.pl
/bin/configure
/bin/login.pl
/bol.cgi
/browse/CSCD-4753
/bugs/index.php
/bugzilla-tip/report.cgi
/bugzilla/editflagtypes.cgi
/c%3dAE
/cBclw7uUuO4
/cade/dot-it-yourself.cgi
/calweb/calweb.exe
/campas
/cart.cgi
/ccbill/whereami.cgi
/cd-cgi/sscd_suncourier.pl
/censtore.cgi
/cgi-auth/userreg.cgi
/cgi-bin
/cgi-bin/.cobalt/message/message.cgi
/cgi-bin/AT-generate.cgi
/cgi-bin/DCShop/Auth_data/auth_user_file.txt
/cgi-bin/DCShop/Orders/orders.txt
/cgi-bin/FileSeek.cgi
/cgi-bin/HASync/hasync.cgi
/cgi-bin/MANGA/admin.cgi
/cgi-bin/MANGA/admin.cgi.
/cgi-bin/SGB_DIR/superguestconfig
/cgi-bin/SetRS422Settings
/cgi-bin/Web_Store/web_store.cgi
/cgi-bin/YaBB.pl
/cgi-bin/YaBB/YaBB.cgi
/cgi-bin/acctman/amadmin.pl
/cgi-bin/admin.cgi
/cgi-bin/admin/artikeladmin.cgi
/cgi-bin/admin/edit_startseitentext.cgi
/cgi-bin/admin/index.cgi
/cgi-bin/admin/param
/cgi-bin/admin/rubrikadmin.cgi
/cgi-bin/admin/setup_edit.cgi
/cgi-bin/admin/shophilfe_suche.cgi
/cgi-bin/adspro/dhtml.pl
/cgi-bin/amlite/amadmin.pl
/cgi-bin/anacondaclip.pl
/cgi-bin/anyboard.cgi/
/cgi-bin/apcupsd.cgi
/cgi-bin/apexec.pl
/cgi-bin/applyConfig.p
/cgi-bin/athcgi.exe
/cgi-bin/auction/auction.cgi
/cgi-bin/authLogin.cgi
/cgi-bin/awl/auctionweaver.pl
/cgi-bin/awstats-6.4/awstats.pl
/cgi-bin/awstats.cgi
/cgi-bin/awstats.pl
/cgi-bin/bb-hostsvc.sh
/cgi-bin/bbs/read.cgi
/cgi-bin/betsie/parserl.pl/<script>alert(
/cgi-bin/bfenterprise/
/cgi-bin/bfgather.exe/actionsite
/cgi-bin/bgplg
/cgi-bin/bizdb1-search.cgi
/cgi-bin/bizdir/bizdir.cgi
/cgi-bin/bizmail/bizmail.cgi
/cgi-bin/boardpower/icq.cgi
/cgi-bin/boozt/admin/index.cgi
/cgi-bin/budmail/data/admin.dat
/cgi-bin/c32web.exe/CheckError
/cgi-bin/c32web.exe/ShowAdminDir
/cgi-bin/c32web.exe/ShowProgress
/cgi-bin/cached_feed.cgi
/cgi-bin/cachemgr.cgi
/cgi-bin/cal_make.pl
/cgi-bin/calendar/Visitor.cgi
/cgi-bin/calender.pl
/cgi-bin/calender_admin.pl
/cgi-bin/captive.cgi
/cgi-bin/cart.pl
/cgi-bin/cart32.exe/error
/cgi-bin/cart32.exe/justsocks-AddIte
/cgi-bin/ccbill/whereami.cgi
/cgi-bin/cgi_system
/cgi-bin/cgibox
/cgi-bin/cgiforum.pl
/cgi-bin/cgiwrap/
/cgi-bin/cgiwrap/~nneul/
/cgi-bin/check.cgi
/cgi-bin/chetcpasswd.cgi
/cgi-bin/chklogin.cgi
/cgi-bin/chpasswd.cgi
/cgi-bin/cilla.cg
/cgi-bin/classifieds.cgi
/cgi-bin/classifieds/viewcat.cgi
/cgi-bin/communimail/mailadmin.cgi
/cgi-bin/communimail/templates.cgi
/cgi-bin/config.cgi
/cgi-bin/config.exp
/cgi-bin/connscheduler.cgi
/cgi-bin/contribute.cgi
/cgi-bin/contribute.pl
/cgi-bin/cookie.cgi
/cgi-bin/cookiemonster.cgi
/cgi-bin/counter/nl/ord/lang=english(1)
/cgi-bin/counterfiglet/nc/f=
/cgi-bin/csSearch.cgi
/cgi-bin/cutecast/members/<username>.user
/cgi-bin/dansguardian.pl
/cgi-bin/dcshop.cgi
/cgi-bin/ddns
/cgi-bin/ddns.cgi
/cgi-bin/dhcp.cgi
/cgi-bin/diagnostic.cgi
/cgi-bin/diagnostics
/cgi-bin/directorypro.cgi
/cgi-bin/discus/board-post.cgi
/cgi-bin/dispair.cgi
/cgi-bin/dmzholes.cgi
/cgi-bin/dna/viewAppletFsa.cgi
/cgi-bin/dnewsweb.exe
/cgi-bin/dns.cgi
/cgi-bin/dnsforward.cgi
/cgi-bin/dose.pl
/cgi-bin/drknow.cgi
/cgi-bin/dumpenv.pl
/cgi-bin/e-cms/vis/vis.pl
/cgi-bin/eboard40/index2.cgi
/cgi-bin/empower
/cgi-bin/emsgb/easymsgb.pl
/cgi-bin/environ.pl
/cgi-bin/erba/start/
/cgi-bin/esp
/cgi-bin/exec.cgi
/cgi-bin/extrahd.cgi
/cgi-bin/ffileman.cgi
/cgi-bin/filemanager/utilRequest.cgi
/cgi-bin/firewall.cgi
/cgi-bin/fom/fom.cgi
/cgi-bin/forum/showflat.pl
/cgi-bin/frameworkgui/CSAttack.pl
/cgi-bin/frameworkgui/SEAttack.pl
/cgi-bin/frameworkgui/attachMobileModem.pl
/cgi-bin/frameworkgui/guessPassword.pl
/cgi-bin/ftplocate/flsearch.pl
/cgi-bin/fwhosts.cgi
/cgi-bin/getlog.cgi
/cgi-bin/guestbook.pl
/cgi-bin/guestbook/passwd
/cgi-bin/haydn.exe
/cgi-bin/help/doIt.cgi
/cgi-bin/his-webshop.pl
/cgi-bin/hosts.cgi
/cgi-bin/htmlmgr
/cgi-bin/htmlscript
/cgi-bin/htsearch
/cgi-bin/http
/cgi-bin/ids.cgi
/cgi-bin/ikonboard.cg
/cgi-bin/ikonboard/help.cgi
/cgi-bin/im_trbbs.cgi
/cgi-bin/imagefolio/admin/admin.cgi
/cgi-bin/index.cgi
/cgi-bin/index.pl
/cgi-bin/info2www
/cgi-bin/interaktiv.shop/front/shop_main.cgi
/cgi-bin/interfaces.cgi
/cgi-bin/ion-p
/cgi-bin/ion-p.exe
/cgi-bin/ipinfo.cgi
/cgi-bin/jammail.pl
/cgi-bin/kaiseki.cgi
/cgi-bin/koha/opac-main.pl
/cgi-bin/lmail.pl
/cgi-bin/loadpage.cgi
/cgi-bin/login.cgi
/cgi-bin/logs.cgi/config.dat
/cgi-bin/logs.cgi/firewalllogcountry.dat
/cgi-bin/logs.cgi/firewalllogport.dat
/cgi-bin/logs.cgi/log.dat
/cgi-bin/logs.cgi/proxylog.dat
/cgi-bin/lshop.cgi
/cgi-bin/lsindex2.bat|dir%20c:\[dir]
/cgi-bin/luci
/cgi-bin/luci/
/cgi-bin/luci/;stok=<home-stok_value>/admin/ping
/cgi-bin/luci/;stok=<homeuser-stok_value>/admin/config_export
/cgi-bin/luci/;stok=<stok_value>/admin/ping
/cgi-bin/luci/;stok=<stok_value>/admin/traceroute
/cgi-bin/luci/;stok=d/admin/network/network/
/cgi-bin/luci/;stok=d/admin/system/packages
/cgi-bin/mac.cgi
/cgi-bin/magiccard.cgi
/cgi-bin/mail.cgi
/cgi-bin/mail/nph-mr.cgi
/cgi-bin/mailengine.pl
/cgi-bin/maillist.cgi
/cgi-bin/mainv2
/cgi-bin/man-cgi
/cgi-bin/masterCGI
/cgi-bin/math_sum.mscgi
/cgi-bin/mb.cgi
/cgi-bin/modem.cgi
/cgi-bin/mods/calendar/index.cgi
/cgi-bin/module/sharedobjmanager/firewall/SOMServiceObjDialog
/cgi-bin/module/sharedobjmanager/policy_new/874/PolicyTable
/cgi-bin/mojo/mojo.cgi
/cgi-bin/multihtml.pl
/cgi-bin/munin-cgi-graph/
/cgi-bin/myquiz.pl/ask/
/cgi-bin/nbmember.cgi
/cgi-bin/netauth.cgi
/cgi-bin/netclubs/login.cgi
/cgi-bin/netclubs/vchat/scripts/imessage.cgi
/cgi-bin/netclubs/vchat/scripts/sendim.cgi
/cgi-bin/news/NsVisitor.cgi
/cgi-bin/news/news.cgi
/cgi-bin/nobody/Search.cgi
/cgi-bin/nobody/VerifyCode.cgi
/cgi-bin/non-existent.pl
/cgi-bin/nph-exploitscanget.cgi
/cgi-bin/nph-maillist.pl
/cgi-bin/nph-showlogs.pl
/cgi-bin/nslookup.cgi
/cgi-bin/oj.cgi
/cgi-bin/operator/fileread
/cgi-bin/operator/servetest?cmd=ntp&ServerName=pool.ntp.org&TimeZone=03:00|id||'
/cgi-bin/outgoing.cgi
/cgi-bin/ovpnmain.cgi
/cgi-bin/pals-cgi
/cgi-bin/parse-file
/cgi-bin/password.cgi
/cgi-bin/path_to_file/bsml.pl
/cgi-bin/pcm.cgi
/cgi-bin/perlcal/cal_make.pl
/cgi-bin/perlshop.cgi
/cgi-bin/pingping.cgi
/cgi-bin/pl_web.cgi/util_configlogin_act
/cgi-bin/plusmail
/cgi-bin/plusmail\
/cgi-bin/pnp/select.cgi
/cgi-bin/pnp/select_.cgi
/cgi-bin/portfw.cgi
/cgi-bin/post32.exe|echo%20>c:\text.txt
/cgi-bin/powerup/r.cgi
/cgi-bin/preferences.cgi
/cgi-bin/preview_email.cgi
/cgi-bin/proxy.cgi
/cgi-bin/psunami.cgi
/cgi-bin/public/edconfd.cgi
/cgi-bin/publisher/search.cgi
/cgi-bin/quikstore.cgi
/cgi-bin/rb.cgi
/cgi-bin/read.cgi
/cgi-bin/readfile.cgi
/cgi-bin/reboot.cgi
/cgi-bin/rguest.exe
/cgi-bin/routing.cgi
/cgi-bin/runDiagnostics.cgi
/cgi-bin/rxgoogle.cgi
/cgi-bin/sawmill5
/cgi-bin/sbcgi/sitebuilder.cgi
/cgi-bin/script.xyz
/cgi-bin/scripts/../../this_server/ServerManager.srv
/cgi-bin/scripts/cart.pl
/cgi-bin/search.cgi
/cgi-bin/search/search.cgi
/cgi-bin/search/show.pl
/cgi-bin/sendtemp.pl
/cgi-bin/setup.cgi
/cgi-bin/setup.pl
/cgi-bin/shadow.txt
/cgi-bin/shop.cgi/page=../../../filename.ext
/cgi-bin/shop.plx/SID
/cgi-bin/shopper.cgi
/cgi-bin/shutdown.cgi
/cgi-bin/simplestmail.cgi
/cgi-bin/smallmenu.pl
/cgi-bin/smoothinfo.cgi
/cgi-bin/spboard/board.cgi
/cgi-bin/start.cgi
/cgi-bin/store/agora.cgi
/cgi-bin/subprodemo/subscribe.pl
/cgi-bin/subscribe.pl
/cgi-bin/supervisor/CloudSetup.cgi
/cgi-bin/supervisor/PwdGrp.cgi
/cgi-bin/supervisor/adcommand.cgi
/cgi-bin/system.cgi
/cgi-bin/system_cmd.cgi
/cgi-bin/test-cgi
/cgi-bin/time.cgi
/cgi-bin/timedaccess.cgi
/cgi-bin/tseekdir.cgi
/cgi-bin/ttt-in
/cgi-bin/ttt-out
/cgi-bin/ttx.cg
/cgi-bin/ttx.cgi
/cgi-bin/twiki/search/Main
/cgi-bin/updatexlrator.cgi
/cgi-bin/urlfilter.cgi
/cgi-bin/user/Config.cgi
/cgi-bin/userConfig.cgi
/cgi-bin/ustorekeeper.pl
/cgi-bin/view/Codev/DownloadTWiki
/cgi-bin/view/TWiki/TWikiInstallationGuide
/cgi-bin/view/image
/cgi-bin/viewcvs.cgi/viewcvs/
/cgi-bin/viewcvs.cgi/viewcvs/viewcvs/
/cgi-bin/viewsrc.cgi
/cgi-bin/vmail.cgi
/cgi-bin/vpnconn.cgi
/cgi-bin/vpnmain.cgi
/cgi-bin/vtls/vtls.web.gateway
/cgi-bin/vulnerable.cgi
/cgi-bin/w3-msql/
/cgi-bin/wakeonlan.cgi
/cgi-bin/webbbs/webbbs_config.pl
/cgi-bin/webboard/generate.cgi/
/cgi-bin/webcart/webcart.cgi
/cgi-bin/webdriver
/cgi-bin/webevent/webevent.cgi
/cgi-bin/webgais
/cgi-bin/webplus.exe
/cgi-bin/webprocgetpage=html/index.html&errorpage=html/main.html&var:language=en_us&var:menu=setup&var:page=connected&var:subpage=-<script>alert("XSS")</script>)
/cgi-bin/websendmail
/cgi-bin/webutil.pl
/cgi-bin/webviewer_login_page?lang=tu&loginvalue=0&port=0&data3=</script><script>alert(1)</script>
/cgi-bin/wguest.exe
/cgi-bin/whereami.cgi
/cgi-bin/whois.cgi
/cgi-bin/wiki.pl
/cgi-bin/wowza.cgi
/cgi-bin/writefile.cgi
/cgi-bin/wwwthreads/changedisplay.pl
/cgi-bin/wwwthreads/previewpost.pl
/cgi-bin/wxis.exe/iah/
/cgi-bin/xtaccess.cgi
/cgi-bin/zml.cgi
/cgi-data/FastJSData.cgi
/cgi-local/auktion/itemlist.pl
/cgi-local/shop.pl/page
/cgi-mod/index.cgi
/cgi-mod/view_help.cgi
/cgi-script/CSMailto/CSMailto.cg
/cgi-script/csFAQ/csFAQ.cgi
/cgi-sys/FormMail.cgi
/cgi-sys/cgiech
/cgi-sys/cgiecho/login.php
/cgi-sys/guestbook.cgi
/cgi/
/cgi/client.cgi
/cgi/commerce.cgipage
/cgi/email_password.plx
/cgi/example
/cgi/news.cgi
/cgi/ping.cgi
/cgi/surgeftpmgr.cgi
/cgi/vqrespond.pl<SCRIPT>alert(
/cgi/wja
/cgi/wrapper.plx
/cgi/zamfoo/zamfoo_do_change_site_ip.cgi
/cgi/zamfoo/zamfoo_do_restore_zamfoo_backup.cgi
/cgibin/amadmin.pl
/cgilua/
/cgit/cgit.cgi/git/objects
/chat.pl
/check.shtml
/checkLogin.cgi 
/class/ads/
/class/hi.html
/class/index.html
/cloisterblog/journal.pl
/cmcget.cgi  
/codes/zend_s03.txt
/colors_cgi.php
/com/cgi-bin/emsgb/easymsgb.pl
/command
/command.cgi?cat%20/etc/passwd
/compose.pl
/conf
/config/global.conf
/content.pl
/cosign-bin/cosign.cgi
/courses/1/my_course/uploads/_19063_1/
/cp-app.cgi
/cp/rac/nsManager.cgi
/cp06_wifi_m_nocifr.cgi
/cqweb/main
/csPassword.cgi
/cswebadm/diag/cgi-bin/nslookup.pl
/cswebadm/diag/cgi-bin/sendrec.pl
/customer_area/index.cgi
/cw2/admin/
/dana-na/auth/remediate.cgi
/dansguardian/edit.cgi
/dbabble
/deface.html
/default.html
/directory/PJreview_Neo.cgi
/directory/blog.cgi
/directory/genindexpage.cgi
/directory/gotopage.cgi
/dispatch.cgi/0
/display.cgi
/dnscfg.cgi
/do_map
/edit.cgi
/edittag/edittag.cgi
/edittag/edittag.pl
/edittag/edittag_mp.cgi
/edittag/edittag_mp.pl
/edittag/mkpw.cgi
/edittag/mkpw.pl
/edittag/mkpw_mp.cgi
/editwrx/wrx.cgi
/en/support/con_show.php
/enduser/process.cgi
/etc/shadow
/events/reports/view.cgi
/everythingform.cgi
/exploits/1755'],
/explorer_wse/detail.exe
/explorer_wse/favorites.exe
/explorer_wse/ws_irpt.exe
/fcgi-bin/wgsetcgi 
/files/epmp
/files/passwd.txt
/findasus.cgi
/firebook/data/admdat/admin.dat
/foldoc/template.cgi
/fom
/fom.cgi
/form2Ddns.cgi 
/form2userconfig.cgi 
/foro/YaBB.pl
/forum.cgi
/forum/support/dispatch.cgi/0
/frontend/x/htaccess/dohtaccess.html
/getConfigExportFile.cgi
/gi-bin/read.cgi
/go.cgi
/guestbook/
/guestbook/add.html
/guestbook/admin.cgi
/guestbook/users/demo
/gwextranet/scp.dll/nbfile
/gwextranet/scp.dll/sendto
/hc/hc
/help
/home/httpd/html/class/ads/
/homepage/edit.cgi
/html/SetSmarcardSettings.ph
/html/SetSmarcardSettings.php
/i-mall/i-mall.cgi
/idm/siteName/ims_mainconsole_principalpopuphandler.do
/idmmanage/mobjattr.do
/inbox/index.fts
/inbox/message.fts
/index.cgi
/index.pl
/index.shtm
/index.tpl
/innoedit/innoedit.cgi
/item.pl
/kb-bestellsystem/kb_whois.cgi
/kb.cgi
/kbcat.cgi
/koha/opac-main.pl]
/kwok/IT/hardware-list.dll
/lang_check.html
/ldap/cgi-bin/ldacgi.exe
/level1.pl
/links.asp
/log-in.html
/login.cgi
/login.pl
/login/
/login/login-page.cgi
/loginpserr.stm
/lstat/lstat.cgi
/mail-demo/archiv.cgi
/mailfile.cgi
/mailman/admin/mailman/members
/mailman/options/yourlist
/mailman/subscribe/ml-name
/mailman_directory/admin/ml-name
/main.cgi
/members_only/index.cgi
/mfgtst.cgi
/mm5/merchant.mvc&Screen=ACNT&Action=EMPW&Customer_Login=
/mod_perl/inmail.pl
/mod_perl/inshop.pl
/moinmoin/WikiSandBox
/monitor_logs_ctl.cgi
/monitor_manage_logs.cgi
/monitor_realtime_logs.cgi
/my_cgi.cgi
/nagios/cgi-bin/statuswml.cgi
/netboardr.cgi
/new/index.htm
/new/no_sd_file.htm
/new/setup.htm
/nobody/Machine.cgi
/nrd/en/generic/3.5g_router.jsp
/nslookup.cgi
/oliver/gateway/gateway.exe
/ooUFXfUfIs0
/p/mongoose/.
/page.cgi
/pages/htmlos/
/pals-cgi
/parse.pl
/parse_xml.cgi
/passwd
/passwd.txt
/password.htm
/passwordrecovered.cgi
/patch/books.cgi
/pblscg.cgi
/pblsmb.cgi
/pbpgst.cgi
/pbs.cgi
/pdestore.cgi
/perl/webcal.cgi
/perldiver.cgi
/perldiver.pl
/phf
/php.cgi
/php/level.php
/phpinfo.php
/ping.cgi
/pkmslogout
/platinum/platformSettingEdit.cgi?type=>"><script>alert("XXS POC")</script>
/plugins
/plusmail
/pm3/cgi/admin.cgi
/portal/apis/aggrecate_js.cgi
/post.cgi
/ppcal.cgi
/preauth/login.cgi
/preview_cgi.php
/preview_static_cgi.php
/printcal.pl
/prof/attributes/features.jsp
/profile.cgi
/protocol_ftp.php
/psirt/statements.htm
/publique/cgi/cgilua.exe/sys/start.htm
/quikstore.cgi
/quizz.pl/ask/
/rd
/reademail.pl
/regx/wireless/wl_security_2G.asp
/remote_login.pl
/reply.pl
/report.cgi
/reports/73480
/request.cgi
/resetpass/
/restore.cgi
/root/www/api/backup/logout.cgi
/sawmill
/scr.cgi
/scripts/c32web.exe/GetImage
/scripts/cart32.exe/GetLatestBuilds
/scripts/cbag/ag.exe
/scripts/cbgrn/grn.exe/memo/print
/scripts/cbgrn/grn.exe/memo/view
/scripts/cbgrn/grn.exe/phonemessage/add
/scripts/cbgrn/grn.exe/phonemessage/history
/scripts/cbgrn/grn.exe/schedule/user_view
/scripts/cbgrn/grn.exe/schedule/view
/scripts/cbgrn/grn.exe/todo/delete
/scripts/cbgrn/grn.exe/todo/index
/scripts/cbgrn/grn.exe/todo/modify
/scripts/cbgrn/grn.exe/todo/view
/scripts/cbgrn/grn.exe/workflow/print
/scripts/cbgrn/grn.exe/workflow/view
/scripts/common/forgotpasswd.cgi
/scripts/common/profile.cgi
/scripts/convert.bas
/scripts/mailpost.exe
/scripts/s360v2/s360.exe
/scripts/sigmaweb.dll
/scripts/uistrings.cgi
/scripts/webbbs/
/scripts/wgate
/scripts/wgate.dll
/sdctl/comm/lite_auth/
/sdlist
/search
/search.cgi
/search.pl
/search97cgi/vtopic
/searchenginepath/site_searcher.cgi
/sendtemp.pl
/server.np
/server/otre/index/pl
/servers/link.cgi/1008341480/init/edit_action.cgi
/servlet/ContentServer
/session.cgi
/session/adminlogin
/shell/index.cgi
/shop/member_html.cgi
/shop/normal_html.cgi
/showmail.pl
/showpage.cgi
/skeletonz/
/snmp
/snmx-cgi/fcheck.exe 
/sql-ledger/am.pl
/sresult.exe
/stats.pl
/status
/status.cgi
/store/agora.cgi
/support/ikonboard.cgi
/swms
/swms/ms.cgi
/system.cgi
/system_module.cgi
/tarantella/cgi-bin/modules.cgi
/tarantella/cgi-bin/ttawebtop.cgi/
/technote/main.cgi*filename=*
/technote/main.cgi/
/technote/technote/print.cgi
/templ_ex/doc/1.html
/test.ks/file
/test.ks/raw_input
/texis.exe/
/this_server/ServerManager.srv
/tlogin.cgi
/tmp/qq
/tmp/temp_SmartCardKey
/to/psynch/nph-psa.exe
/to/psynch/nph-psf.exe
/toc.pl
/tornado/searcher.exe
/ts.cgi
/ts.exe
/tunnel/link.cgi/
/tunnelform.yaws
/twiki/bin/configure
/uClibc/tree/libc/stdlib/random.c
/uClibc/tree/libc/stdlib/random_r.c
/uapi-cgi/viewer/simple_loglistjs.cgi
/udataobj/webgui/cgi-bin/tuxadm.exe
/uk/aboutUs/
/upgrade.cgi
/user+/neomail.pl
/user.cgi
/user/
/user/advanced.tagz
/user/general.tagz
/user/list.tagz
/user/members.tagz
/user/viewmail.tagz
/userconfigsubmit.cgi
/usr/local/etc/excite/collections/AT-personal.prog
/usr/sbin/sendmail
/way-board/way-board.cgi
/web.tmpl
/web/entry/en/address/adrsList.cgi
/web/entry/en/address/adrsList.cgi   
/web/entry/en/address/adrsSetUserWizard.cgi
/webNewAcct.cgi
/web_reports/cgi-bin/InfoStation.cgi
/web_store.cgi
/webadmin/filter.pl
/webapi/FileStation/file_delete.cgi
/webapi/FileStation/file_share.cgi
/webapi/VideoStation/audiotrack.cgi
/webapi/VideoStation/subtitle.cgi
/webapi/VideoStation/watchstatus.cgi
/webapps/blackboard/execute/viewCatalog
/webauthentication
/webcgi/webbatch.exe
/webglimpse.cgi
/webif/webif.cgi
/webiness/index.php
/webmail/emumail.fcgi
/webmail/init.emu
/webman/forget_passwd.cgi
/webnovel/books.cgi
/webx
/wgarcmin.cgi
/wholite.cgi
/wifi/axisrb.htm
/ws/generic_api_call.pl
/wwwboard.html
/~jed/cgi-bin/test.pl
