Exploiting Xpath Injection

Exploiting XPath injection where applications build XPath/XQuery expressions from unsanitized user input to query XML documents, allowing authentication bypass and blind extraction of the entire XML document (users, passwords, schema) plus out-of-band exfiltration. Activates when login or search features query XML data stores via XPath.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/xalgord@xalgorix/internal/tools/skills/data/web-application-security/exploiting-xpath-injection commit 50e0fe6a1d

Frequently asked questions

npx skillmds@latest add gabrielmoreira/exploiting-xpath-injection