01.09.2015 Views

4.0

1NSchAb

1NSchAb

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

134<br />

Web Application Penetration Testing<br />

<br />

Un6R34kb!e<br />

500<br />

s4tan@hell.com<br />

which will be added to the xmlDB:<br />

<br />

<br />

<br />

gandalf<br />

!c3<br />

0<br />

gandalf@middleearth.com<br />

<br />

<br />

Stefan0<br />

w1s3c<br />

500<br />

Stefan0@whysec.hmm<br />

<br />

<br />

tony<br />

Un6R34kb!e<br />

500<br />

s4tan@hell.com<br />

<br />

<br />

double quotes.<br />

<br />

So if:<br />

$inputValue = foo”<br />

the substitution gives:<br />

<br />

and the resulting XML document is invalid.<br />

• Angular parentheses: > and < - By adding an open or closed angular<br />

parenthesis in a user input like the following:<br />

Username = foo<<br />

the application will build a new node:<br />

<br />

foo

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!