Web Security 22
- Session Management and Cookie Security
- Session Fixation Attack
- XSLT Injection
- XXE (XML External Entity) Injection
- SSI (Server-Side Includes) Injection
- SQL Injection
- Server-Side Request Forgery (SSRF)
- Race Condition
- NoSQL Injection
- SSTI (Server-Side Template Injection)
- Log Poisoning via User-Agent
- Local File Inclusion (LFI) & Path Traversal
- Insecure Direct Object References (IDOR)
- File Upload Vulnerabilities
- Command Injection
- Authentication Bypass
- Access Control
- JSON Web Token (JWT) Security
- CSP & Same-Origin Policy Bypass
- Cross-Site Request Forgery (CSRF)
- XSS (Cross-Site Scripting)
- Content Discovery