Injection¶
Injection flaws share a common root: untrusted data reaches an interpreter that treats it as code or a command rather than literal data. The interpreter can be a SQL engine, a shell, an XML parser, a template engine, or a deserializer. The fix is always the same structural move: separate code from data at the point of construction.
Topics in this section¶
| Doc | Core invariant violated |
|---|---|
| SQL Injection | Query structure is fixed at write time, not runtime |
| NoSQL Injection | Operator keys are not user-controlled |
| OS Command Injection | Shell interpolation never touches user input |
| Path Traversal & LFI | Resolved path stays within authorized base |
| XXE Injection | XML parsers never resolve external entities |
| SSTI | Template rendering context is not user-supplied |
| Insecure Deserialization | Deserialized class is never user-chosen |
| SSRF | Server-initiated requests never use attacker-controlled URLs |
| File Upload | Uploaded content is never executed in server context |
Common escalation chain¶
Injection → code execution → file read → SSRF → lateral movement. SQL injection reaching xp_cmdshell or INTO OUTFILE and LFI reaching log poisoning are the canonical paths. Any injection primitive that reaches a system call or a file write is a potential RCE vector.