QeeqBox
- 199 followers
- Washington, USA
- http://qeeqbox.com
Pinned
Repositories
- cross-site-request-forgery Public
A threat actor may trick an authenticated or trusted victim into executing unauthorized actions on their behalf
- local-file-inclusion Public
A threat actor may cause a vulnerable target to include/retrieve local file
- remote-file-inclusion Public
A threat actor may cause a vulnerable target to include/retrieve remote file
- insecure-deserialization Public
A threat actor may tamper with a stream that gets deserialized on the target, causing the target to access data or perform non-intended actions
- xslt-injection Public
A threat actor may interfere with an application's processing of extensible stylesheet language transformations (XSLT) for extensible markup language (XML) to read or modify data on the target
- server-side-template-injection Public
A threat actor may alter the template syntax on the vulnerable target to execute commands
- sql-injection Public
A threat actor may alter structured query language (SQL) query to read, modify and write to the database or execute administrative commands for further chained attacks
- xxe-injection Public
A threat actor may interfere with an application's processing of extensible markup language (XML) data to view the content of a target's files
- os-command-injection Public
A threat actor may inject arbitrary operating system (OS) commands on target
- open-redirect Public
A threat actor may send a malicious redirection request for a vulnerable target to a victim; the victim gets redirected to a malicious website that downloads an executable file












