Exercises

Exercise Avg. Time Difficulty Solved by Tier
XSL PHP II
This exercise covers the exploitation of a PHP application using XSL
< 1 Hr. medium 237 PRO
API Payments 04
This exercise covers how to abuse a shopping cart allowing users to apply a voucher..
< 1 Hr. medium 1189 PRO
XSL PHP
This exercise covers the exploitation of a PHP application using XSL
< 1 Hr. medium 279 PRO
API Payments 03
This exercise covers a simple payments bypass.
< 1 Hr. medium 1296 PRO
Code Review 18
This exercise is one of our challenges to help you learn how to review real source code
1-2 Hr. medium 377 PRO
CVE-2020-13xxx
This challenge covers the review of a CVE and its patch
< 1 Hr. medium 654 PRO
CVE-2008-5x8x
This challenge covers the review of a CVE and its patch
< 1 Hr. easy 829 PRO
CVE-2022-3x7x1
This challenge covers the review of a CVE and its patch
< 1 Hr. easy 756 PRO
Python Snippet #02
This challenge covers the review of a snippet of code written in Python
< 1 Hr. easy 2021 PRO
Java Snippet #12
This challenge covers the review of a snippet of code written in Java
< 1 Hr. easy 1347 PRO
Java Snippet #11
This challenge covers the review of a snippet of code written in Java
< 1 Hr. easy 1394 PRO
Java Snippet #10
This challenge covers the review of a snippet of code written in Java
< 1 Hr. easy 1499 PRO
API Payments 02
This exercise covers a simple payments bypass.
< 1 Hr. medium 1460 PRO
GCM Nonce Reuse
This challenge covers the impact of nonce reuse on GCM
< 1 Hr. medium 182 PRO
CVE-2019-5x2x
This challenge covers the review of a CVE and its patch
< 1 Hr. medium 605 PRO
Java Snippet #08
This challenge covers the review of a snippet of code written in Java
< 1 Hr. easy 1742 PRO
Java Snippet #07
This challenge covers the review of a snippet of code written in Java
< 1 Hr. easy 1725 PRO
Java Snippet #09
This challenge covers the review of a snippet of code written in Java
< 1 Hr. medium 1364 PRO
API Payments 01 API
This exercise covers a simple payments bypass.
< 1 Hr. easy 1894 PRO
CVE-2022-26xx9
This challenge covers a vulnerable snippet in a real Java application
< 1 Hr. medium 609 PRO
Python Snippet #08
This challenge covers the review of a snippet of code written in Python
< 1 Hr. easy 1583 PRO
Python Snippet #09
This challenge covers the review of a snippet of code written in Python
< 1 Hr. easy 1781 PRO
Python Snippet #07
This challenge covers the review of a snippet of code written in Python
< 1 Hr. easy 1661 PRO
Mongo IDOR
This challenge covers how to exploit an IDOR when Mongo IDs are used
< 1 Hr. medium 1154 PRO
CVE-2005-2x8x
This challenge covers the review of a CVE and its patch
< 1 Hr. hard 632 PRO
CVE-2008-5x8x_ii
This challenge covers the review of a CVE and its patch
< 1 Hr. medium 630 PRO
Python Snippet #06
This challenge covers the review of a snippet of code written in Python
< 1 Hr. easy 1794 PRO
Java Snippet #06
This challenge covers the review of a snippet of code written in Java
< 1 Hr. medium 1390 PRO
Golang Snippet #01
This challenge covers the review of a snippet of code written in Golang
< 1 Hr. easy 1766 PRO
CVE-2022-21449 JWT
This exercise covers the exploitation of CVE-2022-21449 against a Java Application relying on JWT
< 1 Hr. medium 177 PRO
1 6 7 8 9 10 11 12 25
Showing 241–270 of 722 exercises