NoSQL injection
Tools
- NoSQL-Attack-Suite
https://github.com/C4l1b4n/NoSQL-Attack-Suite
- Nosql-MongoDB-injection-username-password-enumeration
https://github.com/an0nlk/Nosql-MongoDB-injection-username-password-enumeration
- NoSQLi Scanner Burp Addon
https://portswigger.net/bappstore/605a859f0a814f0cbbdce92bc64233b4
Authentication bypass
Mus be tested manually since NoSQL Injections requires to change the parameters value.
In URL:
In JSON:
Last updated