User inputs
File inclusionUnrestricted file uploadSQL injectionXSS (Cross-Site Scripting)CSRF (Cross-Site Request Forgery)SSRF (Server-Side Request Forgery)IDOR (Insecure Direct Object Reference)ORED Open redirectContent-Type jugglingXXE injectionInsecure JSON Web Tokens🛠️HTTP parameter pollution🛠️SSTI (Server-Side Template Injection)🛠️Insecure deserialization🛠️CRLF injection🛠️Arbitrary file download🛠️Directory traversal🛠️Null-byte injection
Last updated
Was this helpful?