Vulnerabilities
Detectify XSS challenge - Twins of Ten
Ten character XSS payload.
15-07-2015
2 MIN READ
Vulnerabilities
Ten character XSS payload.
2 MIN READ
Vulnerabilities
$_GET['time'] is not escaped.
2 MIN READ
Vulnerabilities
$_REQUEST['items'] is not escaped.
1 MIN READ
Vulnerabilities
We can send email to anyone if we have valid nonce token.
1 MIN READ
Vulnerabilities
$_GET['tab'] is not escaped.
1 MIN READ
Vulnerabilities
When we use word thumb at the begining of $_GET['image'] it's possible to omit preg_match() function.
1 MIN READ
Vulnerabilities
$_GET['tab'] is not escaped.
1 MIN READ
Vulnerabilities
We can read and display any external file using $_REQUEST['code'].
2 MIN READ
From 0 to pentesting hero
Can you expand the potential attack vector for a larger number of applications?
03-04-2019
3 MIN READ