6 high-yield moves from here, ordered the way the engagement runs.
Open any move to see the exact commands.
needsWeb injection point
yieldsWeb injection point
A parameter reflects or errors on your input: you have a confirmed injection point, a vulnerable parameter. Identify the class, then jump to the working exploitation.
start A confirmed web injection point, a vulnerable parameter
1
SQL Injection (SQLi) (errors or boolean/time differences? dump the database)
2
Cross-Site Scripting (XSS) (input reflected into the page? steal sessions)
3
Command Injection (shell metacharacters change the response? get RCE)
4
File Inclusion (LFI / RFI) (a file or path parameter? read files, then RCE)
5
Server-Side Request Forgery (SSRF) (a URL parameter? reach the metadata service)