General Information

Special Element Injection

Variants:
Direct Persistent Session 

Also Known As:
Parameter Delimiter Injection

Vector Type:
Attack

Relevance:
Generic

Layer:
Application-Level

Platforms:
Any

Target Type:
Application

Affected Mechanisms:
Input Validation

Invented In:
11/04/2008

Added In:
08/12/2014


Vector Operation Method:
Malicious inputs containing custom significant characters can cause unexpected behaviors


Direct Variant:

Special Element Injection

Variant Title:
Special Element Injection

Typical Severity:
Medium

Learn More:


Persistent Variant:

Stored Special Element Injection

Also Known As:
Persistent Special Element Injection

Typical Severity:
Medium

Resources:

White Papers:

Learn More:


Session Variant:

Special Element Injection via Session Puzzling

Also Known As:
Session Special Element Injection

Typical Severity:
Medium

Resources:

White Papers:

Learn More: