web application security 14
- ExpressCart Prototype Pollution to Denial Of Service
- SuiteCRM - Phar Deserialization to Code Execution
- ADempiere Unsafe Deserialization to Code Execution
- OpenCATS PHP Object Injection to Arbitrary File Write
- PHP Object Injection Exploitation Notes
- DomGoat Walkthrough
- Common XSS payloads I use
- Ghost Publishing Platform – SVG Image Upload to Stored Cross-site scripting
- phppgadmin CSRF to Code Execution
- The target="_blank" Vulnerability
- Ganglia Reflected XSS
- Finding SQL Injection vulnerabilities using polyglot payloads
- Exploiting Local File Inclusion using PHP Wrappers
- ZAP Scripting