Exercises

Exercise Avg. Time Difficulty Solved by Tier
OAuth2: Authorization Server XSS II
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. hard 286 PRO
OAuth2: Authorization Server XSS
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. medium 399 PRO
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
1-2 Hr. hard 382 PRO
XSS Include XSS
This exercise covers how to use Cross-Site-Scripting Include to leak information
< 1 Hr. easy 1379 PRO
SVG XSS
This exercise covers how to use an SVG to trigger a Cross-Site-Scripting
< 1 Hr. medium 1900 PRO
XSS 09 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9431 PRO
XSS 10 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 8726 PRO
XSS 02 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 11179 PRO
XSS 03 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 10753 PRO
XSS 04 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 10228 PRO
XSS 05 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9957 PRO
XSS 06 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9850 PRO
XSS 07 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9682 PRO
XSS 08 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9522 PRO
XSS 01 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 11834 PRO
XSS and MySQL FILE XSS
This exercise explains how to exploit a Cross-Site Scripting vulnerability to obtain an administrator's cookies, and how you can use their session to gain access to the administration panel, and find a SQL injection to gain code execution
-- medium 0 FREE
Showing 1–16 of 16 exercises