Tools
LDAP Blind Explorer: Tool for automating LDAP Injection. This small utility lets you extract any arbitrary attribute from the LDAP server.
http://code.google.com/p/ldap-blind-explorer/
XPATH Blind explorer: Tool for automating XPATH Injection. This utility helps you automate the exploitation of XPATH Injection and let you download the entire XML file from the vulnerable application. You can even read the comments within the XML file. The tool only supports XPATH 1.0.
http://code.google.com/p/xpath-blind-explorer/

