WSTG - Latest
4.7 Injection
4.7.1 Reflected Cross Site Scripting
4.7.2 Stored Cross Site Scripting
4.7.3 HTTP Verb Tampering
4.7.4 HTTP Parameter Pollution
4.7.5 SQL Injection
-
4.7.5.1 Oracle
-
4.7.5.2 MySQL
-
4.7.5.3 SQL Server
-
4.7.5.4 PostgreSQL
-
4.7.5.5 MS Access
-
4.7.5.6 NoSQL Injection
-
4.7.5.7 ORM Injection
-
4.7.5.8 Client-side
4.7.6 LDAP Injection
4.7.7 XML Injection
4.7.8 SSI Injection
4.7.9 XPath Injection
4.7.10 IMAP SMTP Injection
4.7.11 Code Injection
- 4.7.11.1 File Inclusion
4.7.12 Command Injection
4.7.13 Format String Injection
4.7.14 Incubated Vulnerability
4.7.15 HTTP Response Splitting
4.7.16 HTTP Request Smuggling
4.7.17 Host Header Injection
4.7.18 Server-side Template Injection
4.7.19 Server-Side Request Forgery
4.7.20 Mass Assignment
4.7.21 CSV Injection
4.7.22 Prototype Pollution
4.7.23 Insecure Deserialization