logo

Database

001. SQL injection - C Sharp SQL API004. Remote command execution008. Reflected cross-site scripting (XSS)010. Stored cross-site scripting (XSS)012. SQL injection - Java Persistence API021. XPath injection045. HTML code injection063. Lack of data validation - Path Traversal083. XML injection (XXE)089. Lack of data validation - Trust boundary violation090. CSV injection096. Insecure deserialization105. Apache lucene query injection106. NoSQL injection107. LDAP injection112. SQL injection - Java SQL API121. HTTP parameter pollution127. Lack of data validation - Type confusion141. Lack of data validation - URL146. SQL injection154. Time-based SQL Injection155. SQL Injection - Headers184. Lack of data validation185. Lack of data validation - Header x-amzn-RequestId186. Lack of data validation - Web Service187. Lack of data validation - Source Code188. Lack of data validation - Modify DOM Elements189. Lack of data validation - Content Spoofing190. Lack of data validation - Session Cookie191. Lack of data validation - Responses192. Lack of data validation - Reflected Parameters193. Lack of data validation - Host Header Injection194. Lack of data validation - Input Length195. Lack of data validation - Headers196. Lack of data validation - Dates197. Lack of data validation - Numbers198. Lack of data validation - Out of range199. Lack of data validation - Emails274. Restricted fields manipulation297. SQL injection - Code321. Lack of data validation - HTML code323. XML injection (XXE) - Unmarshaller340. Lack of data validation - Special Characters341. Lack of data validation - OTP344. Lack of data validation - Non Sanitized Variables353. Lack of data validation - Token361. Missing secure obfuscation - JavaScript362. Technical information leak - Content response363. Weak credential policy - Password strength364. Weak credential policy - Temporary passwords365. Authentication mechanism absence or evasion - Response tampering371. DOM-Based cross-site scripting (XSS)390. Prototype Pollution422. Server side template injection425. Server side cross-site scripting429. Universal cross-site scripting (UXSS)430. Serverless - one dedicated IAM role per function434. Client-side template injection438. Error-based SQL Injection442. SMTP header injection450. Blind-based SQL injection451. OData injection452. Prompt injection454. Improper output handling