in each parameter in
turn. If no error occurs, your input is probably not being inserted into a
SOAP message, or is being sanitized in some way.
■
If an error was received, submit instead a valid opening and closing tag
pair, such as
. If this causes the error to disappear, then the
application may well be vulnerable.
■
In some situations, data that is inserted into an XML-formatted message
is subsequently read back from its XML form and returned to the user. If
the item you are modifying is being returned in the application’s
responses, see whether any XML content you submit is returned in its
identical form, or has been normalized in some way. Submit the follow-
ing two values in turn:
test
test
Do'stlaringiz bilan baham: |