⚔️
Pentest CodeX
search
⌘Ctrlk
LinkedInGithub
⚔️
Pentest CodeX
  • Home
    • WHOAMI
  • Network Pentest
    • Recon
    • Enumeration
      • Application Enumeration
      • Network Enumeration
      • Service Enumeration
      • Web Enumeration
        • Accounts and sessions
        • Configuration
        • Reconnaissance
        • User inputs
          • API
          • Arbitrary file download
          • Content-Type juggling
          • CRLF injection
          • CSRF (Cross-Site Request Forgery)
          • Directory traversal
          • HTTP parameter pollution
          • IDOR (Insecure Direct Object Reference)
          • Insecure deserialization
          • Insecure JSON Web Tokens
          • Null-byte injection
          • ORED Open redirect
          • SQL injection
          • SSRF (Server-Side Request Forgery)
          • SSTI (Server-Side Template Injection)
          • Unrestricted file upload
          • XSS (Cross-Site Scripting)
          • XXE injection
          • File inclusion
    • Exploitation
    • Pre Exploitation
    • Post-Exploitation
    • Privilege Escalation
    • Active Directory Attack
  • Courses
    • HTB-CPTS
    • OSCP
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
githubEdit
  1. Network Pentestchevron-right
  2. Enumerationchevron-right
  3. Web Enumeration

User inputs

APIchevron-rightArbitrary file downloadchevron-rightContent-Type jugglingchevron-rightCRLF injectionchevron-rightCSRF (Cross-Site Request Forgery)chevron-rightDirectory traversalchevron-rightHTTP parameter pollutionchevron-rightIDOR (Insecure Direct Object Reference)chevron-rightInsecure deserializationchevron-rightInsecure JSON Web Tokenschevron-rightNull-byte injectionchevron-rightORED Open redirectchevron-rightSQL injectionchevron-rightSSRF (Server-Side Request Forgery)chevron-rightSSTI (Server-Side Template Injection)chevron-rightUnrestricted file uploadchevron-rightXSS (Cross-Site Scripting)chevron-rightXXE injectionchevron-rightFile inclusionchevron-right
PreviousWeb Application Firewall (WAF)chevron-leftNextAPIchevron-right

Last updated 10 months ago