XPATH injection
Basic Syntax
Nodes
Examples:
Predicates
Unknown Nodes
Examples:
Example
Authentication Bypass
Example of queries:
OR bypass in user and password (same value in both)
Abusing null injection
Double OR in Username or in password (is valid with only 1 vulnerable field)
String extraction
Blind Explotation
Get length of a value and extract it by comparisons:
Example:
References
PreviousWeb Tool - WFuzzNextXSLT Server Side Injection (Extensible Stylesheet Languaje Transformations)
Last updated