File

File injection groups the attacks that abuse how a web application takes in, resolves, and emits files rather than how it builds a query.

Three tracks run through this subtree. Upload covers getting attacker-controlled bytes written to a path the server will later execute or serve, including web-shell planting and archive extraction that escapes its target directory. Inclusion covers dynamic include/require style sinks where a path or URL fragment is attacker-controlled, yielding source disclosure, local file reads, and code execution. Exports covers the opposite direction: data the application writes out (CSV, LaTeX, PDF) that a downstream program parses and interprets, turning an export feature into command execution or data theft on another system. Each technique page carries concrete, runnable payloads.

Cookie Consent

We use cookies to enhance your experience. Learn more