PHP Injection Audit

PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发。 覆盖 6 种注入: SQL 注入(PDO/MySQLi/ORM)、NoSQL 注入(MongoDB)、 命令注入(system/exec/passthru)、LDAP 注入、表达式注入(eval/preg_replace /e)、SSRF。 需要 php-audit-pipeline 提供的数据流证据(EVID_*)作为审计输入。

wgpsec 28ad655 2 files · 15.0 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/code-audit/php/php-injection-audit commit 28ad655bae

Frequently asked questions

npx skillmds@latest add wgpsec/php-injection-audit