Exercises

Exercise Avg. Time Difficulty Solved by Tier
OAuth2: Authorization Server XSS II
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. hard 281 PRO
OAuth2: Authorization Server XSS
This exercise covers the exploitation of an XSS in an OAuth2 Authorization Server
< 1 Hr. medium 386 PRO
OAuth2: Client Server XSS
This exercise covers the exploitation of a Cross-Site Scripting in an OAuth2 Client and Server
1-2 Hr. hard 378 PRO
XSS Include XSS
This exercise covers how to use Cross-Site-Scripting Include to leak information
< 1 Hr. easy 1365 PRO
SVG XSS
This exercise covers how to use an SVG to trigger a Cross-Site-Scripting
< 1 Hr. medium 1827 PRO
XSS 09 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9181 PRO
XSS 10 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 8468 PRO
XSS 02 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 10817 PRO
XSS 03 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 10387 PRO
XSS 04 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 9912 PRO
XSS 05 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9646 PRO
XSS 06 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9541 PRO
XSS 07 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9416 PRO
XSS 08 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. medium 9268 PRO
XSS 01 XSS
This exercise is one of our challenges on Cross-Site Scripting
< 1 Hr. easy 11322 PRO
XSS and MySQL FILE XSS
This exercise explains how to exploit a Cross-Site Scripting vulnerability to obtain an administrator's cookies, and how you can use their session to gain access to the administration panel, and find a SQL injection to gain code execution
-- medium 0 FREE
Showing 1–16 of 16 exercises