beafn28
⌘Ctrlk
beafn28
  • 👩‍💻¡Bienvenidos a mi HackBook!
    • DockerLabs
    • TryHackMe
    • HackTheBox
    • Vulnhub
    • The Hacker Labs
    • Vulnyx
    • OverTheWire
    • Proving Ground Play
    • Pentesting Basics
    • Network Enumeration with NMAP
    • Footprinting
    • Information Gathering - Web Edition
    • Vulnerability Assessment
    • Nessus
    • OpenVAS
    • Reporting
    • File Transfers
    • Shells & Payloads
    • Metasploit
    • Password Attacks
    • Introduction Active Directory
    • Active Directory Enumeration & Attacks
    • Hacking Android
    • Web Requests
    • Introduction to Web Applications
    • Using Web Proxies
    • Introduction Gathering - Web Edition
    • Attacking Web Applications with FFUZ
    • JavaScript Deobfuscation
    • Cross-Site-Scripting (XSS)
    • SQL Injection Fundamentals
    • SQLMap Essentials
    • Introducción Red Team
    • Active Directory (Cheat Sheet 1)
    • Active Directory (Cheat Sheet 2)
    • Path Traversal
    • SQL Injection
    • Control de Acceso
    • Laboratorios PortSwigger
      • SQL Injection
      • Authentication
      • Path Traversal
      • OS command injection
      • Business logic vulnerabilities
      • Information disclosure
      • Access control
      • File upload vulnerabilities
      • Race conditions
      • Server-side request forgery (SSRF)
      • XML external entity (XXE) injection
      • Cross-site scripting
      • Cross-site request forgery (CSRF)
      • Clickjacking
      • DOM-based vulnerabilities
      • API testing
      • HTTP request smuggling
      • WebSockets
      • Web cache poisoning
      • Insecure deserialization
      • HTTP Host header attacks
      • OAuth authentication
      • JWT
      • Essential Skills
      • Prototype pollution
      • GraphQL API vulnerabilities
      • NoSQL injection
      • Web LLM attacks
      • Web cache deception
      • Cross-origin resource sharing (CORS)
      • Server-side template injection
    • Curso web s4vitar
    • BSCP (Cheat Sheet)
    • Pequeñas Mentirosas
    • Bancarrota
    • CryptoLabyrinth
    • Elevator
    • Facultad
    • Requiem Cipher
    • Máquinas
    • Curso de Mario
    • Información
    • Máquinas
    • eJPTv2
    • eWPTXv3
    • eCPPTv3
    • CRTA
    • ICCA
    • MCRTA
    • AD-RTS
    • CRT-ID
    • eMAPTv2
    • CWES
    • Brute Force Login Vulnerability in Soosyze CMS 2.0 (CVE-2025-52392)
    • PoC - CVE-2025-9140 (Lingdang CRM 8.6.4.7)- SQL Injection
    • Broken Access Control in LibreTime analytics endpoints (CVE-2025-60427)
    • WordPress Upload.am – Contributor+ Arbitrary Option Disclosure (CVE-2025-12630)
    • Directus < 11.13.0 – Improper Permission Handling on Deleted Fields (CVE-2025-64746)
    • nopCommerce <= 4.70 and 4.80.3 – Insufficient Session Cookie Invalidation (CVE-2025-11699)
    • Typesetter CMS Reflected XSS via Editing Component (CVE-2025-71164)
    • Typesetter CMS Reflected XSS via Status.php (CVE-2025-71165)
    • Typesetter CMS Reflected XSS via Move Message Handling (CVE-2025-71166)
    • PoC - CVE-2025-10327 (RPi-Jukebox-RFID 2.8.0) – Remote Command Execution
    • birkir prime GraphQL GET-Based CSRF (CVE-2025-15550)
    • FluentCMS Stored XSS via SVG Upload in File Management (CVE-2025-15549)
    • PoC - CVE-2025-10666 (D-Link DIR-825 Rev.B ≤ 2.10) - Stack Buffer Overflow (DoS)
    • PoC - CVE-2025-10370 (RPi-Jukebox-RFID 2.8.0) - Stored Cross-Site Scripting (XSS)
    • LavaLite CMS Stored XSS via Package Creation and Search (CVE-2025-71177)
    • PoC - CVE-2024-23334 (aiohttp ≤ 3.9.1) - Directory Traversal via follow_symlinks
    • PoC - Ingress-NGINX Admission Controller File Descriptor Injection to RCE (Varios CVE asociados)
    • PoC - CVE-2025-32023 (Redis) - Remote Code Execution (RCE)
    • PoC - CVE-2025-24054 - Windows NTLM Hash Disclosure via .library-ms Spoofing
    • PoC - CVE-2023-4911 - glibc “Looney Tunables” Local Privilege Escalations
    • PoC - CVE-2025-24054 - Windows NTLM Hash Disclosure / Spoofing
    • Bludit CMS CSRF in Plugin and Theme Management Endpoints (CVE-2026-27741)
    • Bludit CMS Stored XSS in Post Content (CVE-2026-27742)
    • GetSimpleCMS-CE Stored XSS via components.php (CVE-2026-26351)
    • Bio-Formats XXE in Leica Metadata Parser (CVE-2026-22186)
    • PoC- CVE-2025-4524 - Local File Inclusion (WordPress Madara)
    • PoC - CVE-2025-34040 - Arbitrary File Upload to RCE (Zhiyuan OA)
    • PoC- CVE-2025-4123 - SSRF / XSS via Open Redirect (Grafana)
    • SSCMS SQL Injection via stl:sqlContent queryString (CVE-2026-7435)
    • SSCMS Reflected Cross-Site Scripting via STL Processing (CVE-2026-7429)
Powered by GitBook
  1. WEB SECURITY

Laboratorios PortSwigger

SQL InjectionCross-site scriptingCross-site request forgery (CSRF)ClickjackingDOM-based vulnerabilitiesCross-origin resource sharing (CORS)XML external entity (XXE) injectionServer-side request forgery (SSRF)HTTP request smugglingOS command injectionServer-side template injectionPath TraversalAccess controlAuthenticationWebSocketsWeb cache poisoningInsecure deserializationInformation disclosureBusiness logic vulnerabilitiesHTTP Host header attacksOAuth authenticationFile upload vulnerabilitiesJWTEssential SkillsPrototype pollutionGraphQL API vulnerabilitiesRace conditionsNoSQL injectionAPI testingWeb LLM attacksWeb cache deception
PreviousControl de AccesoNextSQL Injection

Last updated 11 months ago