OWASP 3-Blind XPATH Injection
●▬▬▬۩❁ @InfoSecTube❁۩▬▬▬▬●
OWASP Attacks Crash Course
XPath is a type of query language that describes how to locate specific elements (including attributes, processing instructions, etc.) in an XML document. Since it is a query language, XPath is somewhat similar to Structured Query Language (SQL), however, XPath is different in that it can be used to reference almost any part of an XML document without access control restrictions. In SQL, a “user” (which is a term undefined in the XPath/XML context) may be restricted to certain databases, tables, columns, or queries. Using an XPATH Injection attack, an attacker is able to modify the XPATH query to perform an action of his choosing.
Instructor:@BiskooitPedar
▬▬▬۩❁ @InfoSecTube ❁۩▬▬▬▬●
Telegram Channel:
http://bit.ly/2AONyvP
Subscribe to this channel if… you enjoy fun and educational videos about technology & CyberSecurity & ...OWASP1 Binary Planting@BiskooitPedar