Email injections
Emails injection: XSS, SQLi, SSTI, etc.
user[email][]=valid@email.com&user[email][]=attacker@email.comJSON
{"email":["mymail@b.com", "attacker@x.com"]}
{"email":"mymail@b.com", "email":"attacker@x.com"}
email=attacker@x.comPunnycode
Registration FormParser Abuse - Domain confusion
oastify.com!collab\@example.com
collab%psres.net(@example.comXSS
XSSSSTI
SSRF
CRLF
CRLF InjectionPassword ResetSQL Injection
SQL InjectionCommand Injection
Command InjectionOpen Redirection
Bypass Access Control
HTML injection - Subscription form
Resources
Interesting Books
Interesting BooksSupport this Gitbook
Last updated
