Nosql Injection

NoSQL 注入检测与利用。当目标使用 MongoDB/CouchDB 等 NoSQL 数据库、登录表单使用 JSON body 提交、或参数中出现 $gt/$ne/$regex 等操作符时使用。覆盖操作符注入认证绕过、$regex 盲注数据提取、$where JS 注入、CouchDB 攻击、WAF 绕过

wgpsec 34a1a75 2 files · 12.5 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/exploit/web-method/nosql-injection commit 34a1a75023

Frequently asked questions

npx skillmds@latest add wgpsec/nosql-injection