Ir al contenido
cyberhub.es
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2025 writeup
      • PicoCTF 2024 writeup
  • PortSwigger Lab Writeups
  • Home
  • CTFs resueltos
    • PicoCTF
      • PicoCTF 2025 writeup
      • PicoCTF 2024 writeup
  • PortSwigger Lab Writeups

Categoría: writeups

SQL injection attack, querying the database type and version on MySQL and Microsoft

SQL injection attack, querying the database type and version on Oracle

Exploiting XSS to bypass CSRF defenses

Reflected XSS into a JavaScript string with angle brackets and double quotes HTML-encoded and single quotes escaped

Reflected XSS into a JavaScript string with single quote and backslash escaped

Reflected XSS in canonical link tag

Reflected XSS with some SVG markup allowed

Reflected XSS into HTML context with all tags blocked except custom ones

Reflected XSS into HTML context with most tags and attributes blocked

Stored DOM XSS

← Anterior
Siguiente →
cyberhub.es
  • Política de Cookies

Todos los derechos reservados