> For the complete documentation index, see [llms.txt](https://docs.prophaze.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prophaze.com/protection-use-cases/injection-prevention.md).

# Injection Prevention

Prophaze WAF can prevent the following Injection attacks

* OS Command Injection -  Exploiting arbitrary commands in the operating system to fingerprint Infrastructure details , and to establish a trust between host operating Systems . This happens when application passes unsafe data which Includes Forms , Cookies , URL Arguments etc
* Coldfusion Injection – Prevents database injection in Coldfusion apps
* LDAP Injection - Stops exploits which attacks LDAP Protocol
* SSI Injection – Prevents attacks which manipulates server side Includes to execute remote code injections
* UPDF/XSS Injection – Prevents XSS attacks on applications with pdf Files
* Email Injection – Prevents Email Injection where attacker utilizes Carriage return to inject extra email headers to the contact form
* Blocks system command access
* Blocks Directory Traversal attacks
