> For the complete documentation index, see [llms.txt](https://kryptocoder.gitbook.io/hacking-knowledge/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kryptocoder.gitbook.io/hacking-knowledge/web-exploitation-wip/web-vulnerabilities-wip/injection-wip.md).

# Injection (WIP)

A type of attack where untrusted data is sent to an interpreter, which can manipulate it to execute unintended actions. Normally, it occurs when we find a way of sending HTML, CSS, JS code, database queries, and others, via a request, a form, a website URL, among others.

We can find several ways of carrying out this type of attack:

* [**Cross-Site Scripting (XSS):**](/hacking-knowledge/web-exploitation-wip/web-vulnerabilities-wip/cross-site-scripting-wip.md) Injects malicious JavaScript code into a web page
* [**SQL Injection (SQLi):**](/hacking-knowledge/database-attacks/attack-techniques/sql-injection.md) Injects malicious SQL queries into a database, poisoning structured database queries based on SQL with the user input, or even NoSQL database queries
* [**Command Injection:**](/hacking-knowledge/web-exploitation-wip/web-vulnerabilities-wip/os-command-injection-wip.md) Executes arbitrary system commands on a server or application
* [**Server-Side Template Injection (SSTI):**](/hacking-knowledge/web-exploitation-wip/web-vulnerabilities-wip/server-side-template-injection-wip.md) Inject template syntax that is improperly handled or validated into applications that use template engines
* **LDAP Injection:** Manipulates LDAP queries for unauthorized directory access
* **XPath Injec**tion: Alters *XML* Path Language (XPath) queries for unauthorized access to *XML* data
* [**XXE Injection:**](/hacking-knowledge/web-exploitation-wip/web-vulnerabilities-wip/xxe-injection-wip.md) Manipulates *XML* data or queries to inject malicious data
* **SMTP/Email Injection:** Exploits vulnerabilities in email systems to inject malicious emails
* **Expression Language (EL) Injection:** Injects malicious input into Expression Language (used in Java-based applications)
* **CRLF Injection:** Injects carriage return and line feed characters into HTTP headers to manipulate responses
