
Common web vulnerabilities every hacker and developer should know
We’ve put together a list of the most visited Detectify blog posts on common web vulnerabilities to help anyone interested in hacking and defending: Web …

Detectify Admin

With many potential attack vectors, cross-site scripting (XSS) is a widespread vulnerability that affects a large number of sites. Check out this list of our XSS resources to learn more about the vulnerability and stay up to date with alerts.
Our OWASP TOP 10 posts offer an insight into each of the 10 vulnerability types on OWASP’s list. We describe the vulnerabilities, the impact they can have, and highlight well-known examples of events involving them. Of course, we also explain how to discover these vulnerabilities, providing code examples and helpful remediation tips.
Cross-site scripting is a type of attack that can be carried out to compromise users of a website. The exploitation of an XSS flaw enables the attacker to inject client-side scripts into web pages viewed by users. It is often assumed XSS only occurs in JavaScript, but it could also include e.g. VBScript.
Read about the different types of Cross-site scripting and the impact they can have on your site and its users.
If you’re looking for Cross-site Scripting examples complete with solutions, this blog post is for you!
XSS is one of the top four critical vulnerabilities on websites we scan. To find out how we discover vulnerabilities and get an insight into how our scanner works, take a look behind the scenes with our data scientist Andrea Palaia.
Read our knowledge advisor Frans Rosén’s account of how he discovered and reported a stored XSS on Facebook.
For more XSS-related content, check out our Labs blog where we publish technical write-ups and examples of various exploits.

We’ve put together a list of the most visited Detectify blog posts on common web vulnerabilities to help anyone interested in hacking and defending: Web …

TL;DR: On January 7, the Detectify security research team found that the .cd top-level domain (TLD) was about to be released for anyone to purchase and claimed …