Injection
Untrusted input reaching an interpreter — SQL, commands, templates and the query underneath.
A quote that breaks the login query
Break out of a query or a shell command through unescaped input.
The search filter that trusts your input
Break out of a query or a shell command through unescaped input.
A serialized cart the client can edit
Feed the server a serialized object it will trust and rebuild.
Error-based extraction from a chatty endpoint
Break out of a query or a shell command through unescaped input.
The role hidden in a base64 cookie
Feed the server a serialized object it will trust and rebuild.
UNION-selecting the users table
Break out of a query or a shell command through unescaped input.
A file type check you can talk past
Turn a foothold into commands running on the server itself.
An upload that lands in an executable path
Turn a foothold into commands running on the server itself.
Boolean-blind, one bit at a time
Break out of a query or a shell command through unescaped input.
Second-order injection through a stored value
Break out of a query or a shell command through unescaped input.
Tampering with a signed-but-unverified token
Feed the server a serialized object it will trust and rebuild.
Time-based extraction from a silent endpoint
Break out of a query or a shell command through unescaped input.
Type confusion in a rebuilt object
Feed the server a serialized object it will trust and rebuild.
A dependency confusion package that runs on install
Turn a foothold into commands running on the server itself.
A gadget chain to state change
Feed the server a serialized object it will trust and rebuild.
Argument injection into a called binary
Turn a foothold into commands running on the server itself.
Command injection through a filename
Break out of a query or a shell command through unescaped input.
From deserialization gadget to shell
Turn a foothold into commands running on the server itself.
From deserialization to file write
Feed the server a serialized object it will trust and rebuild.
Reading files through the database engine
Break out of a query or a shell command through unescaped input.
Stacking queries to write, not just read
Break out of a query or a shell command through unescaped input.
Template injection to command execution
Turn a foothold into commands running on the server itself.
XXE escalated to a file read and beyond
Turn a foothold into commands running on the server itself.