beafn28
Ctrlk
  • 👩‍💻¡Bienvenidos a mi HackBook!
  • WRITEUPS
    • DockerLabs
    • TryHackMe
    • HackTheBox
    • Vulnhub
    • The Hacker Labs
    • Vulnyx
    • OverTheWire
    • Proving Ground Play
  • APUNTES HACKING
    • Pentesting Basics
    • Network Enumeration with NMAP
    • Footprinting
    • Information Gathering - Web Edition
    • Vulnerability Assessment
    • Nessus
    • OpenVAS
    • Reporting
    • File Transfers
    • Shells & Payloads
    • Metasploit
    • Password Attacks
    • Introduction Active Directory
    • Active Directory Enumeration & Attacks
    • Hacking Android
    • Web Requests
    • Introduction to Web Applications
    • Using Web Proxies
    • Introduction Gathering - Web Edition
    • Attacking Web Applications with FFUZ
    • JavaScript Deobfuscation
    • Cross-Site-Scripting (XSS)
    • SQL Injection Fundamentals
    • SQLMap Essentials
    • Introducción Red Team
    • Active Directory (Cheat Sheet 1)
    • Active Directory (Cheat Sheet 2)
  • WEB SECURITY
    • Path Traversal
    • SQL Injection
    • Control de Acceso
    • Laboratorios PortSwigger
      • SQL Injection
      • Authentication
      • Path Traversal
      • OS command injection
      • Business logic vulnerabilities
      • Information disclosure
      • Access control
      • File upload vulnerabilities
      • Race conditions
      • Server-side request forgery (SSRF)
      • XML external entity (XXE) injection
      • Cross-site scripting
      • Cross-site request forgery (CSRF)
      • Clickjacking
      • DOM-based vulnerabilities
      • API testing
      • HTTP request smuggling
      • WebSockets
      • Web cache poisoning
      • Insecure deserialization
      • HTTP Host header attacks
      • OAuth authentication
      • JWT
      • Essential Skills
      • Prototype pollution
      • GraphQL API vulnerabilities
      • NoSQL injection
      • Web LLM attacks
      • Web cache deception
      • Cross-origin resource sharing (CORS)
      • Server-side template injection
    • Curso web s4vitar
    • BSCP (Cheat Sheet)
  • Mis CTFs
    • Pequeñas Mentirosas
    • CryptoLabyrinth
    • Elevator
    • Facultad
  • PREPARAR EJPTv2
    • Máquinas
    • Curso de Mario
  • Preparar OSCP
    • Información
    • Máquinas
  • Reviews Certificaciones
    • eJPTv2
    • eWPTXv3
    • eCPPTv3
    • CRTA
    • ICCA
    • MCRTA
    • AD-RTS
    • CRT-ID
    • eMAPTv2
  • CVE
    • Brute Force Login Vulnerability in Soosyze CMS 2.0 (CVE-2025-52392)
    • PoC - CVE-2025-9140 (Lingdang CRM 8.6.4.7)- SQL Injection
    • Broken Access Control in LibreTime analytics endpoints (CVE-2025-60427)
    • WordPress Upload.am – Contributor+ Arbitrary Option Disclosure (CVE-2025-12630)
    • Directus < 11.13.0 – Improper Permission Handling on Deleted Fields (CVE-2025-64746)
    • nopCommerce <= 4.70 and 4.80.3 – Insufficient Session Cookie Invalidation (CVE-2025-11699)
Powered by GitBook
On this page
  1. WEB SECURITY
  2. Laboratorios PortSwigger

Prototype pollution

PreviousEssential SkillsNextGraphQL API vulnerabilities

Was this helpful?

Was this helpful?