Skip to main content

exploiting-xpath-injection

Exploiting XPath injection where applications build XPath/XQuery expressions from unsanitized user input to query XML documents, allowing authentication bypass and blind extraction of the entire XML document (users, passwords, schema) plus out-of-band exfiltration. Activates when login or search features query XML data stores via XPath.

インストールへ移動

ソース情報

リポジトリ
xalgord/xalgorix
ソースの最終更新活動
2026年6月6日 16:41
検出された SKILL.md の言語
英語
スター
813
フォーク
146

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。