Attack Web — validation index

Attack Web — validation index

Important

Test only owned or explicitly authorized applications. Use synthetic users and canary data, fixed endpoints, a request budget, preserved application/proxy/database telemetry, a minimum proof, a stop condition, and verified cleanup. Start with Web Security Index and Web Validation Catalog.

The entries below name software weaknesses or abuse cases. They are not interchangeable with ATT&CK tactics, OWASP categories, or CVEs.

Weakness or abuse case Description How It Works Benign lab proof
SQL Injection (SQLi) Injects malicious SQL into input fields to manipulate DB queries Attacker modifies query to extract or manipulate data SELECT * FROM users WHERE id='1' OR '1'='1'
Cross-Site Scripting (XSS) Injects malicious scripts into web pages Scripts execute in the victim’s browser <script>alert('XSS')</script>
Cross-Site Request Forgery (CSRF) Forces users to execute unwanted actions Exploits authenticated sessions by tricking browser <img src="http://target/delete?user=1">
Remote Code Execution (RCE) Executes attacker-controlled code on the server Input is passed directly to system functions Return a random marker from a disposable fixture; do not open a shell
Directory Traversal Accesses files outside the web root Manipulates file paths using ../ /download?file=../../etc/passwd
File Upload Vulnerability Uploads malicious files to the server Server allows unsafe file types or paths Uploading shell.php and accessing it via URL
Command Injection Injects system commands through user input Input passed unsanitized to shell commands ping 127.0.0.1; whoami
Insecure Deserialization Executes code by deserializing untrusted input Malformed serialized objects trigger code execution Java/PHP object with injected payload
Broken Access Control Bypasses restrictions to access unauthorized data/functions Direct access to APIs/URLs without proper checks Accessing /admin without being admin
Server-Side Request Forgery (SSRF) Causes the server to make an unintended request A server-side fetch accepts an insufficiently constrained URL Request one owned canary endpoint and correlate application, DNS, and egress logs