NoSQL injection

Exploit
Basic authentication bypass
SQL - Mongo
Extract length information
Extract data information
SQL - Mongo
PHP Arbitrary Function Execution

Get info from different collection

MongoDB Payloads
Blind NoSQL Script
Brute-force login usernames and passwords from POST login
Tools
References

Last updated

