MongoDB
Injection in insert
by YesWeHack
drag_indicator
drag_indicator
drag_indicator
Modifying the collection
This time the injection point is in an insert statement, Try to inject an extra filed in you maillinglist entry
Goal: Insert an entry with {"HACK": "YesWeHack"}
Solution
drag_indicator
INPUT
OUTPUT
drag_indicator
drag_indicator