6:02URL-based access control can be circumvented PortSwigger Academy tutorialPink Boo120 views·1 month ago
3:54User role can be modified in user profile PortSwigger Academy tutorialPink Boo65 views·2 months ago
2:51User role controlled by request parameter PortSwigger Academy tutorialPink Boo64 views·2 months ago
2:53Unprotected admin functionality with unpredictable URL PortSwigger Academy tutorialPink Boo64 views·2 months ago
5:04Information disclosure in version control history PortSwigger Academy tutorial GitHub DesktopPink Boo134 views·2 months ago
5:05Authentication bypass via information disclosure PortSwigger Academy tutorialPink Boo91 views·2 months ago
3:39Soure code disclosure via backup files PortSwigger Academy tutorial ffuf fuzzingPink Boo65 views·2 months ago
5:56Information disclosure on debug page PortSwigger Academy tutorial FFUF tutorialPink Boo121 views·2 months ago
5:22Information disclosure in error messages PortSwigger Academy tutorial Owasp Juice Shop tutorialPink Boo332 views·4 months ago
7:10Remote code execution via polyglot web shell upload PortSwigger Academy tutorialPink Boo348 views·5 months ago
5:22Web shell upload via obfuscated file extension PortSwigger Academy tutorialPink Boo214 views·5 months ago
4:37Web shell upload via extension blacklist bypass PortSwigger Academy tutorialPink Boo2.6K views·1 year ago
3:33Web shell upload via Content-Type restriction bypass PortSwigger Academy tutorialPink Boo1.9K views·1 year ago
4:14Remote code execution via web shell upload PortSwigger Academy tutorialPink Boo3.4K views·1 year ago
6:15JWT authentication bypass via algorithm confusion with no exposed key PortSwigger Academy tutorialPink Boo1.5K views·1 year ago
7:02JWT authentication bypass via algorithm confusion PortSwigger Academy tutorialPink Boo2.3K views·1 year ago
3:23JWT authentication bypass via kid header path traversal PortSwigger Academy tutorialPink Boo1.4K views·1 year ago
4:28JWT authentication bypass via jku header injection PortSwigger Academy tutorialPink Boo2.2K views·2 years ago
4:15JWT authentication bypass via jwk header injection PortSwigger Academy tutorialPink Boo2.0K views·2 years ago
4:37JWT authentication bypass via weak signing key PortSwigger Academy tutorialPink Boo3.2K views·2 years ago
4:06JWT authentication bypass via flawed signature verification PortSwigger Academy tutorialPink Boo1.9K views·2 years ago
3:55JWT authentication bypass via unverified signature PortSwigger Academy tutorialPink Boo3.7K views·2 years ago
5:29Exfiltrating sensitive data via server-side prototype pollution PortSwigger Academy tutorialPink Boo955 views·2 years ago
5:16Remote code execution via server-side prototype pollution PortSwigger Academy tutorialPink Boo1.6K views·2 years ago
2:20Bypassing flawed input filters for server-side prototype pollution PortSwigger Academy tutorialPink Boo750 views·2 years ago
4:55Detecting server-side prototype pollution without polluted property reflection PortSwiggerPink Boo1.0K views·2 years ago
4:01Privilege escalation via server-side prototype pollution PortSwigger Academy tutorialPink Boo1.4K views·2 years ago