MongoDB NoSQL Injection via Aggregation Pipelines!

preview_player
Показать описание
Add parameters like $lookup, $unionWith, and $match to your wordlist for testing. Any errors or hits on these might give a hint to a potential NoSQL injection.

Shout out to Soroush Dalili for this research!
Рекомендации по теме