|
.github
|
Fix nested lists
|
2024-11-03 17:10:52 +01:00 |
|
_LEARNING_AND_SOCIALS
|
Normalize page header for API, CSPT, CORS, CSRF
|
2024-11-09 23:01:39 +01:00 |
|
_template_vuln
|
Normalize page header for API, CSPT, CORS, CSRF
|
2024-11-09 23:01:39 +01:00 |
|
Account Takeover
|
Account Takeover References
|
2024-11-03 21:22:14 +01:00 |
|
API Key Leaks
|
Normalize page header for API, CSPT, CORS, CSRF
|
2024-11-09 23:01:39 +01:00 |
|
Business Logic Errors
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Clickjacking
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Client Side Path Traversal
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Command Injection
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
CORS Misconfiguration
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
CRLF Injection
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Cross-Site Request Forgery
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
CSV Injection
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
CVE Exploits
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Denial of Service
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Dependency Confusion
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
Directory Traversal
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
DNS Rebinding
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
DOM Clobbering
|
Normalize page header for CSRF, DNS, DOS, Dependencies
|
2024-11-10 11:18:46 +01:00 |
|
File Inclusion
|
References updated for Dom Clobbering, File Inclusion
|
2024-11-05 17:29:15 +01:00 |
|
Google Web Toolkit
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
GraphQL Injection
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Headless Browser
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Hidden Parameters
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
HTTP Parameter Pollution
|
References added for GWT, GraphQL, HTTP, Headless
|
2024-11-06 23:32:18 +01:00 |
|
Insecure Deserialization
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Insecure Direct Object References
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Insecure Management Interface
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Insecure Randomness
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Insecure Source Code Management
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
Java RMI
|
Normalize page header for GraphQL, Deserialization, SCM
|
2024-11-10 14:37:48 +01:00 |
|
JSON Web Token
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
LaTeX Injection
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
LDAP Injection
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
Mass Assignment
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
Methodology and Resources
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
NoSQL Injection
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
OAuth Misconfiguration
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
Open Redirect
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
ORM Leak
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
Prompt Injection
|
References updated for NoSQL, OAuth, ORM, Prompt, RegEx
|
2024-11-07 16:20:58 +01:00 |
|
Prototype Pollution
|
Normalize page header for JWT, LDAP, LaTeX, OAuth, ORM
|
2024-11-10 15:28:12 +01:00 |
|
Race Condition
|
References updated for NoSQL, OAuth, ORM, Prompt, RegEx
|
2024-11-07 16:20:58 +01:00 |
|
Regular Expression
|
References updated for NoSQL, OAuth, ORM, Prompt, RegEx
|
2024-11-07 16:20:58 +01:00 |
|
Request Smuggling
|
References updated for SAML, SSI, SSRF
|
2024-11-07 18:31:21 +01:00 |
|
SAML Injection
|
References updated for SAML, SSI, SSRF
|
2024-11-07 18:31:21 +01:00 |
|
Server Side Include Injection
|
References updated for SAML, SSI, SSRF
|
2024-11-07 18:31:21 +01:00 |
|
Server Side Request Forgery
|
References updated for SAML, SSI, SSRF
|
2024-11-07 18:31:21 +01:00 |
|
Server Side Template Injection
|
References addded for SQLi, Upload, SSTI, Type Juggling
|
2024-11-07 20:54:16 +01:00 |
|
SQL Injection
|
Normalize page header for API, CSPT, CORS, CSRF
|
2024-11-09 23:01:39 +01:00 |
|
Tabnabbing
|
References addded for SQLi, Upload, SSTI, Type Juggling
|
2024-11-07 20:54:16 +01:00 |
|
Type Juggling
|
References addded for SQLi, Upload, SSTI, Type Juggling
|
2024-11-07 20:54:16 +01:00 |
|
Upload Insecure Files
|
References addded for SQLi, Upload, SSTI, Type Juggling
|
2024-11-07 20:54:16 +01:00 |
|
Web Cache Deception
|
References updated for XPATH, XSLT, XXE, Web Socket
|
2024-11-07 23:50:30 +01:00 |
|
Web Sockets
|
References updated for XPATH, XSLT, XXE, Web Socket
|
2024-11-07 23:50:30 +01:00 |
|
XPATH Injection
|
References updated for XPATH, XSLT, XXE, Web Socket
|
2024-11-07 23:50:30 +01:00 |
|
XSLT Injection
|
References updated for XPATH, XSLT, XXE, Web Socket
|
2024-11-07 23:50:30 +01:00 |
|
XSS Injection
|
References updated for XSS + page splitted in subcategories
|
2024-11-08 18:23:43 +01:00 |
|
XXE Injection
|
References updated for XPATH, XSLT, XXE, Web Socket
|
2024-11-07 23:50:30 +01:00 |
|
Zip Slip
|
References addded for SQLi, Upload, SSTI, Type Juggling
|
2024-11-07 20:54:16 +01:00 |
|
.gitignore
|
YAML Deserialization
|
2022-09-16 16:37:40 +02:00 |
|
CONTRIBUTING.md
|
PR Guidelines + User Hunting + HopLa Configuration
|
2022-06-30 16:33:35 +02:00 |
|
custom.css
|
CSS - Update style color + Blind SQL Oracle
|
2023-12-10 13:27:21 +01:00 |
|
LICENSE
|
Create License
|
2019-05-25 16:27:35 +02:00 |
|
mkdocs.yml
|
SSTI references updates
|
2024-11-03 20:54:01 +01:00 |
|
README.md
|
Fix typos
|
2024-09-16 18:05:54 +02:00 |