Web Application Security
Category overview
6
Topics
39
Lessons
Learning topics
Explore Web Application Security
Choose a topic and start building your security skills.
SQL Injection
Server-SideA comprehensive study of SQL injection vulnerabilities, exploitation techniques, detection, impact, testing methodology, and production-grade prevention.
Cross-Site Scripting (XSS)
Client-SideCross-Site Scripting (XSS) is a client-side injection vulnerability where an attacker gets their own script to run inside another user's browser, in the security context of a website that user already trusts.
Authentication Vulnerabilities
BothAuthentication vulnerabilities are weaknesses that allow an attacker to access an account or protected resource without properly proving that they are the legitimate user.
Authorization and Access Control
Server-SideAuthorization determines what an authenticated user is allowed to access or perform. Access control ensures these permissions are enforced so users cannot access resources or functionality beyond their assigned privileges.
Session Management
Server-SideSession management vulnerabilities occur when an application incorrectly creates, stores, transmits, validates, or invalidates authenticated sessions.
Cross Site Request Forgery
Server-SideCSRF is a server-side vulnerability in which an attacker causes a victim's browser to send a malicious or unintended request to the target application where the victim is authenticated. If the server does not have adequate CSRF protection, it may execute the malicious request and treat it as a legitimate request from the authenticated user.