This content represents the latest contributions to the Web Security Testing Guide, and may frequently change.
OWASP logo
Store Donate Join

This website uses cookies to analyze our traffic and only share that information with our analytics partners.

Accept
x
Store
Donate
Join

WSTG - Latest

Home > Latest > 4-Web Application Security Testing > 07-Injection

4.7 Injection

4.7.1 Reflected Cross Site Scripting

4.7.2 Stored Cross Site Scripting

4.7.3 HTTP Verb Tampering

4.7.4 HTTP Parameter Pollution

4.7.5 SQL Injection

  • 4.7.5.1 Oracle

  • 4.7.5.2 MySQL

  • 4.7.5.3 SQL Server

  • 4.7.5.4 PostgreSQL

  • 4.7.5.5 MS Access

  • 4.7.5.6 NoSQL Injection

  • 4.7.5.7 ORM Injection

  • 4.7.5.8 Client-side

4.7.6 LDAP Injection

4.7.7 XML Injection

4.7.8 SSI Injection

4.7.9 XPath Injection

4.7.10 IMAP SMTP Injection

4.7.11 Code Injection

  • 4.7.11.1 File Inclusion

4.7.12 Command Injection

4.7.13 Format String Injection

4.7.14 Incubated Vulnerability

4.7.15 HTTP Response Splitting

4.7.16 HTTP Request Smuggling

4.7.17 Host Header Injection

4.7.18 Server-side Template Injection

4.7.19 Server-Side Request Forgery

4.7.20 Mass Assignment

4.7.21 CSV Injection

4.7.22 Prototype Pollution

4.7.23 Insecure Deserialization


Watch Star
The OWASP® Foundation works to improve the security of software through its community-led open source software projects, hundreds of chapters worldwide, tens of thousands of members, and by hosting local and global conferences.

WSTG Contents

  • 0. Foreword
  • 1. About
  • 2. Introduction
    • 2.1 Purpose and Scope
    • 2.2 Why Web Application Security Testing Matters
    • 2.3 Who Should Use This Guide
    • 2.4 Core Principles of Effective Security Testing
    • 2.5 How the Guide Is Organized
    • 2.6 How to Reference WSTG Scenarios
    • 2.7 Feedback and Comments
    • 2.8 Related OWASP Projects
  • 3. The OWASP Testing Framework
    • 3.1 The Web Security Testing Framework
    • 3.2 Phase 1 Before Development Begins
    • 3.3 Phase 2 During Definition and Design
    • 3.4 Phase 3 During Development
    • 3.5 Phase 4 During Deployment
    • 3.6 Phase 5 During Maintenance and Operations
    • 3.7 A Typical SDLC Testing Workflow
    • 3.8 Penetration Testing Methodologies
  • 4. Web Application Security Testing
    • 4.0 Introduction and Objectives
    • 4.1 Information Gathering
      • 4.1.1 Conduct Search Engine Reconnaissance for Information Leakage
      • 4.1.2 Fingerprint Web Server
      • 4.1.3 Review Webserver Metafiles for Information Leakage
      • 4.1.4 Attack Surface Identification
      • 4.1.5 Review Web Page Content for Information Leakage
      • 4.1.6 Identify Application Entry Points
      • 4.1.7 Map Execution Paths Through Application
      • 4.1.8 Fingerprint Web Application Framework
      • 4.1.9 Fingerprint Web Application
      • 4.1.10 Map Application Architecture
    • 4.2 Configuration and Deployment Management
      • 4.2.1 Network Infrastructure Configuration
      • 4.2.2 Application Platform Configuration
      • 4.2.3 File Extensions Handling for Sensitive Information
      • 4.2.4 Review Old Backup and Unreferenced Files for Sensitive Information
      • 4.2.5 Enumerate Infrastructure and Application Admin Interfaces
      • 4.2.6 HTTP Methods
      • 4.2.7 HTTP Strict Transport Security
      • 4.2.8 RIA Cross Domain Policy
      • 4.2.9 File Permission
      • 4.2.10 Subdomain Takeover
      • 4.2.11 Cloud Storage
      • 4.2.12 Content Security Policy
      • 4.2.13 Path Confusion
      • 4.2.14 Other HTTP Security Header Misconfigurations
    • 4.3 Identity Management
      • 4.3.1 Role Definitions
      • 4.3.2 User Registration Process
      • 4.3.3 Account Provisioning Process
      • 4.3.4 Account Enumeration and Guessable User Account
      • 4.3.5 Weak or Unenforced Username Policy
    • 4.4 Authentication
      • 4.4.1 Credentials Transported over an Encrypted Channel
      • 4.4.2 Default Credentials
      • 4.4.3 Weak Lock Out Mechanism
      • 4.4.4 Bypassing Authentication Schema
      • 4.4.5 Vulnerable Remember Password
      • 4.4.6 Browser Cache Weaknesses
      • 4.4.7 Weak Authentication Methods
      • 4.4.8 Weak Security Question Answer
      • 4.4.9 Weak Password Change or Reset Functionalities
      • 4.4.10 Weaker Authentication in Alternative Channel
      • 4.4.11 Multi-Factor Authentication
    • 4.5 Authorization
      • 4.5.1 Directory Traversal File Include
      • 4.5.2 Bypassing Authorization Schema
      • 4.5.3 Privilege Escalation
      • 4.5.4 Insecure Direct Object References
      • 4.5.5 OAuth Weaknesses
        • 4.5.5.1 OAuth Authorization Server Weaknesses
        • 4.5.5.2 OAuth Client Weaknesses
    • 4.6 Session Management
      • 4.6.1 Session Management Schema
      • 4.6.2 Cookies Attributes
      • 4.6.3 Session Fixation
      • 4.6.4 Exposed Session Variables
      • 4.6.5 Cross Site Request Forgery
      • 4.6.6 Logout Functionality
      • 4.6.7 Session Timeout
      • 4.6.8 Session Puzzling
      • 4.6.9 Session Hijacking
      • 4.6.10 JSON Web Tokens
      • 4.6.11 Concurrent Sessions
    • 4.7 Injection
      • 4.7.1 Reflected Cross Site Scripting
      • 4.7.2 Stored Cross Site Scripting
      • 4.7.3 HTTP Verb Tampering
      • 4.7.4 HTTP Parameter Pollution
      • 4.7.5 SQL Injection
        • 4.7.5.1 Oracle
        • 4.7.5.2 MySQL
        • 4.7.5.3 SQL Server
        • 4.7.5.4 PostgreSQL
        • 4.7.5.5 MS Access
        • 4.7.5.6 NoSQL Injection
        • 4.7.5.7 ORM Injection
        • 4.7.5.8 Client-side
      • 4.7.6 LDAP Injection
      • 4.7.7 XML Injection
      • 4.7.8 SSI Injection
      • 4.7.9 XPath Injection
      • 4.7.10 IMAP SMTP Injection
      • 4.7.11 Code Injection
        • 4.7.11.1 File Inclusion
      • 4.7.12 Command Injection
      • 4.7.13 Format String Injection
      • 4.7.14 Incubated Vulnerability
      • 4.7.15 HTTP Response Splitting
      • 4.7.16 HTTP Request Smuggling
      • 4.7.17 Host Header Injection
      • 4.7.18 Server-side Template Injection
      • 4.7.19 Server-Side Request Forgery
      • 4.7.20 Mass Assignment
      • 4.7.21 CSV Injection
      • 4.7.22 Prototype Pollution
      • 4.7.23 Insecure Deserialization
    • 4.8 Error Handling
      • 4.8.1 Improper Error Handling
      • 4.8.2 Stack Traces
    • 4.9 Weak Cryptography
      • 4.9.1 Weak Transport Layer Security
      • 4.9.2 Padding Oracle
      • 4.9.3 Sensitive Information Sent via Unencrypted Channels
      • 4.9.4 Weak Cryptographic Primitives
    • 4.10 Business Logic
      • 4.10.0 Introduction to Business Logic
      • 4.10.1 Business Logic Data Validation
      • 4.10.2 Ability to Forge Requests
      • 4.10.3 Integrity Checks
      • 4.10.4 Process Timing
      • 4.10.5 Number of Times a Function Can Be Used Limits
      • 4.10.6 Circumvention of Work Flows
      • 4.10.7 Defenses Against Application Misuse
      • 4.10.8 Upload of Unexpected File Types
      • 4.10.9 Upload of Malicious Files
      • 4.10.10 Payment Functionality
    • 4.11 Client-side
      • 4.11.1 DOM-Based Cross Site Scripting
        • 4.11.1.1 Self DOM Based Cross-Site Scripting
      • 4.11.2 JavaScript Execution
      • 4.11.3 HTML Injection
      • 4.11.4 Client-side URL Redirect
      • 4.11.5 CSS Injection
      • 4.11.6 Client-side Resource Manipulation
      • 4.11.7 Cross Origin Resource Sharing
      • 4.11.8 Cross Site Flashing
      • 4.11.9 Clickjacking
      • 4.11.10 WebSockets
      • 4.11.11 Web Messaging
      • 4.11.12 Browser Storage
      • 4.11.13 Cross Site Script Inclusion
      • 4.11.14 Reverse Tabnabbing
      • 4.11.15 Client-side Template Injection
    • 4.12 API Testing
      • 4.12.0 API Testing Overview
      • 4.12.1 API Reconnaissance
      • 4.12.2 API Broken Object Level Authorization
      • 4.12.3 Excessive Data Exposure
      • 4.12.4 API Broken Function Level Authorization
      • 4.12.99 GraphQL
  • 5. Reporting
    • 5.1 Reporting Structure
    • 5.2 Naming Schemes
  • Appendix A. History
  • Appendix B. Testing Tools Resource
  • Appendix C. Suggested Reading
  • Appendix D. Fuzzing
  • Appendix E. Encoded Injection
  • Appendix F. Leveraging Dev Tools

Upcoming OWASP Global Events

Corporate Supporters

Become a corporate supporter
  • HOME
  • PROJECTS
  • CHAPTERS
  • EVENTS
  • ABOUT
  • PRIVACY
  • SITEMAP
  • CONTACT

OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc. Unless otherwise specified, all content on the site is Creative Commons Attribution-ShareAlike v4.0 and provided without warranty of service or accuracy. For more information, please refer to our General Disclaimer. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. Copyright 2026, OWASP Foundation, Inc.