Exercises

Exercise Avg. Time Difficulty Solved by Tier
OAuth2: Authorization Server XSS II
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. hard 282 PRO
OAuth2: Authorization Server XSS
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. medium 392 PRO
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
1-2 Hr. hard 379 PRO
XSS Include XSS
This exercise covers how to use Cross-Site-Scripting Include to leak information
< 1 Hr. easy 1374 PRO
SVG XSS
This exercise covers how to use an SVG to trigger a Cross-Site-Scripting
< 1 Hr. medium 1883 PRO
XSS 09 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9321 PRO
XSS 10 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 8632 PRO
XSS 02 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 11018 PRO
XSS 03 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 10608 PRO
XSS 04 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 10103 PRO
XSS 05 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9833 PRO
XSS 06 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9729 PRO
XSS 07 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9564 PRO
XSS 08 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9409 PRO
XSS 01 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 11652 PRO
XSS and MySQL FILE XSS
This exercise explains how to exploit a Cross-Site Scripting vulnerability to obtain an administrator's cookies, and how you can use their session to gain access to the administration panel, and find a SQL injection to gain code execution
-- medium 0 FREE
Showing 1–16 of 16 exercises