寻求OWASP ZAP全量告警名称文档,需注入类告警准确拼写
Got it! I’ve pulled together the exact official names of injection-related alerts from OWASP ZAP that you’re looking for—these are the exact strings you’ll see in ZAP’s alerts and rule sets:
- Remote OS Command Injection – The one you’ve already identified, confirmed as the official name
- SSI Injection – Server-Side Includes Injection, exact ZAP alert name
- XML External Entity (XXE) Injection – Full official name for XXE; sometimes abbreviated to XXE Injection in quick references
- SQL Injection – Standard SQL injection alert, includes sub-variants like Error-Based SQL Injection but the parent category uses this name
- LDAP Injection – Exact name for LDAP query injection alerts
- XPATH Injection – Official name for XPath query injection
- Command Injection (Generic) – A broader category for command injection cases that don’t fit the remote OS-specific variant
- Template Injection – For template engine injection vulnerabilities (e.g., Jinja2, Twig)
- NoSQL Injection – Exact name for NoSQL database injection alerts
- CRLF Injection – Carriage Return Line Feed injection, classified under injection-related alerts
- Header Injection – HTTP header injection alert
- Mail Header Injection – Specific alert for email header injection
- XQuery Injection – Official name for XQuery injection vulnerabilities
To double-check, you can also navigate to ZAP’s Rules menu, filter for "injection" in the rule search bar, and verify these names directly in the built-in rule definitions—they’ll match exactly what’s used in scan alerts and reports.
内容的提问来源于stack exchange,提问作者postoronnim
相关产品推荐
相关产品推荐

