beafn28
⌘Ctrlk
beafn28
  • 👩‍💻¡Bienvenidos a mi HackBook!
    • DockerLabs
    • TryHackMe
    • HackTheBox
    • Vulnhub
    • The Hacker Labs
    • Vulnyx
    • OverTheWire
    • Proving Ground Play
    • Pentesting Basics
    • Network Enumeration with NMAP
    • Footprinting
    • Information Gathering - Web Edition
    • Vulnerability Assessment
    • Nessus
    • OpenVAS
    • Reporting
    • File Transfers
    • Shells & Payloads
    • Metasploit
    • Password Attacks
    • Introduction Active Directory
    • Active Directory Enumeration & Attacks
    • Hacking Android
    • Web Requests
    • Introduction to Web Applications
    • Using Web Proxies
    • Introduction Gathering - Web Edition
    • Attacking Web Applications with FFUZ
    • JavaScript Deobfuscation
    • Cross-Site-Scripting (XSS)
    • SQL Injection Fundamentals
    • SQLMap Essentials
    • Introducción Red Team
    • Active Directory (Cheat Sheet 1)
    • Active Directory (Cheat Sheet 2)
    • Path Traversal
    • SQL Injection
    • Control de Acceso
    • Laboratorios PortSwigger
      • SQL Injection
      • Authentication
      • Path Traversal
      • OS command injection
      • Business logic vulnerabilities
      • Information disclosure
      • Access control
      • File upload vulnerabilities
      • Race conditions
      • Server-side request forgery (SSRF)
      • XML external entity (XXE) injection
      • Cross-site scripting
      • Cross-site request forgery (CSRF)
      • Clickjacking
      • DOM-based vulnerabilities
      • API testing
      • HTTP request smuggling
      • WebSockets
      • Web cache poisoning
      • Insecure deserialization
      • HTTP Host header attacks
      • OAuth authentication
      • JWT
      • Essential Skills
      • Prototype pollution
      • GraphQL API vulnerabilities
      • NoSQL injection
      • Web LLM attacks
      • Web cache deception
      • Cross-origin resource sharing (CORS)
      • Server-side template injection
    • Curso web s4vitar
    • BSCP (Cheat Sheet)
    • Pequeñas Mentirosas
    • Bancarrota
    • CryptoLabyrinth
    • Elevator
    • Facultad
    • Requiem Cipher
    • Máquinas
    • Curso de Mario
    • Información
    • Máquinas
    • eJPTv2
    • eWPTXv3
    • eCPPTv3
    • CRTA
    • ICCA
    • MCRTA
    • AD-RTS
    • CRT-ID
    • eMAPTv2
    • CWES
    • Brute Force Login Vulnerability in Soosyze CMS 2.0 (CVE-2025-52392)
    • PoC - CVE-2025-9140 (Lingdang CRM 8.6.4.7)- SQL Injection
    • Broken Access Control in LibreTime analytics endpoints (CVE-2025-60427)
    • WordPress Upload.am – Contributor+ Arbitrary Option Disclosure (CVE-2025-12630)
    • Directus < 11.13.0 – Improper Permission Handling on Deleted Fields (CVE-2025-64746)
    • nopCommerce <= 4.70 and 4.80.3 – Insufficient Session Cookie Invalidation (CVE-2025-11699)
    • Typesetter CMS Reflected XSS via Editing Component (CVE-2025-71164)
    • Typesetter CMS Reflected XSS via Status.php (CVE-2025-71165)
    • Typesetter CMS Reflected XSS via Move Message Handling (CVE-2025-71166)
    • PoC - CVE-2025-10327 (RPi-Jukebox-RFID 2.8.0) – Remote Command Execution
    • birkir prime GraphQL GET-Based CSRF (CVE-2025-15550)
    • FluentCMS Stored XSS via SVG Upload in File Management (CVE-2025-15549)
    • PoC - CVE-2025-10666 (D-Link DIR-825 Rev.B ≤ 2.10) - Stack Buffer Overflow (DoS)
    • PoC - CVE-2025-10370 (RPi-Jukebox-RFID 2.8.0) - Stored Cross-Site Scripting (XSS)
    • LavaLite CMS Stored XSS via Package Creation and Search (CVE-2025-71177)
    • PoC - CVE-2024-23334 (aiohttp ≤ 3.9.1) - Directory Traversal via follow_symlinks
    • PoC - Ingress-NGINX Admission Controller File Descriptor Injection to RCE (Varios CVE asociados)
    • PoC - CVE-2025-32023 (Redis) - Remote Code Execution (RCE)
    • PoC - CVE-2025-24054 - Windows NTLM Hash Disclosure via .library-ms Spoofing
    • PoC - CVE-2023-4911 - glibc “Looney Tunables” Local Privilege Escalations
    • PoC - CVE-2025-24054 - Windows NTLM Hash Disclosure / Spoofing
    • Bludit CMS CSRF in Plugin and Theme Management Endpoints (CVE-2026-27741)
    • Bludit CMS Stored XSS in Post Content (CVE-2026-27742)
    • GetSimpleCMS-CE Stored XSS via components.php (CVE-2026-26351)
    • Bio-Formats XXE in Leica Metadata Parser (CVE-2026-22186)
    • PoC- CVE-2025-4524 - Local File Inclusion (WordPress Madara)
    • PoC - CVE-2025-34040 - Arbitrary File Upload to RCE (Zhiyuan OA)
    • PoC- CVE-2025-4123 - SSRF / XSS via Open Redirect (Grafana)
    • SSCMS SQL Injection via stl:sqlContent queryString (CVE-2026-7435)
    • SSCMS Reflected Cross-Site Scripting via STL Processing (CVE-2026-7429)
Powered by GitBook
  1. WEB SECURITY
  2. Laboratorios PortSwigger

Web cache poisoning

PreviousWebSocketsNextInsecure deserialization