Ninjasworkout:-- Vulnerable NodeJS Web Application.
ADDED BUGS:-
Prototype Pollution
1

No SQL Injection
2

Cross site Scripting
3

Broken Access Control
4

Broken Session Management
5

Weak Regex Implementation
6

Race Condition
7

CSRF -Cross Site Request Forgery
8

Weak Bruteforce Protection
9

User Enumeration
10

Reset Password token leaking in Referrer
11

Reset Password bugs
12

Sensitive Data Exposure
13

Unicode Case Mapping Collision
14

File Upload
15

SSRF
16

XXE
Open Redirection
17

Directory Traversal
18

Insecure Deserilization => Remote Code Execution
19

Server Side Template Injection 
🚶


Timing Attack 
🚶


Disclaimer:- This project was created for educational purposes and should not be used in environments without legal authorization.
Visit Us:- https://ncybersecurity.com
Call/WA:- +918016167754
E-mail:- [email protected]
National Cyber Security Services
#cybersecurity #CyberSecurityNews #infosec #infosecurity #cybersecurityawareness #informationsecurity #pentesting #cybersecuritytraining #informationtechnology #bugbounty #ethicalhacking #EthicalHackingOnlineTraining #hacking #hackers #kalilinux #onlinetraining #onlineclasses #AWS #cloudcomputing #OWASP
*Beware click the link!