nosql-injection
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides a Python script template using the 'requests' library designed to automate blind data extraction from target databases by enumerating field values using regex operators.\n- [COMMAND_EXECUTION]: Outlines procedures for achieving command execution on target infrastructure, specifically describing how to create a web shell via Redis configuration commands (CONFIG SET) and how to abuse MongoDB's JavaScript environment.\n- [REMOTE_CODE_EXECUTION]: Documents the use of the MongoDB '$where' operator to execute arbitrary JavaScript logic on the database server, enabling logic bypass and time-based extraction oracles.\n- [DYNAMIC_EXECUTION]: Details the injection of query operators and the manipulation of aggregation pipelines to dynamically alter query behavior and bypass security controls.
Audit Metadata