File injection groups the attacks that abuse how a web application takes in, resolves, and emits files rather than how it builds a query.
Three tracks run through this subtree. Upload covers getting attacker-controlled bytes written to a path the server will later execute or serve, including web-shell planting and archive extraction that escapes its target directory. Inclusion covers dynamic include/require style sinks where a path or URL fragment is attacker-controlled, yielding source disclosure, local file reads, and code execution. Exports covers the opposite direction: data the application writes out (CSV, LaTeX, PDF) that a downstream program parses and interprets, turning an export feature into command execution or data theft on another system. Each technique page carries concrete, runnable payloads.