Skip to content

Injection

Injection flaws share a common root: untrusted data reaches an interpreter that treats it as code or a command rather than literal data. The interpreter can be a SQL engine, a shell, an XML parser, a template engine, or a deserializer. The fix is always the same structural move: separate code from data at the point of construction.

Topics in this section

Doc Core invariant violated
SQL Injection Query structure is fixed at write time, not runtime
NoSQL Injection Operator keys are not user-controlled
OS Command Injection Shell interpolation never touches user input
Path Traversal & LFI Resolved path stays within authorized base
XXE Injection XML parsers never resolve external entities
SSTI Template rendering context is not user-supplied
Insecure Deserialization Deserialized class is never user-chosen
SSRF Server-initiated requests never use attacker-controlled URLs
File Upload Uploaded content is never executed in server context

Common escalation chain

Injection → code execution → file read → SSRF → lateral movement. SQL injection reaching xp_cmdshell or INTO OUTFILE and LFI reaching log poisoning are the canonical paths. Any injection primitive that reaches a system call or a file write is a potential RCE vector.