Attack Web — validation index
Attack Web — validation index
Important
Test only owned or explicitly authorized applications. Use synthetic users and canary data, fixed endpoints, a request budget, preserved application/proxy/database telemetry, a minimum proof, a stop condition, and verified cleanup. Start with Web Security Index and Web Validation Catalog.
The entries below name software weaknesses or abuse cases. They are not interchangeable with ATT&CK tactics, OWASP categories, or CVEs.
| Weakness or abuse case | Description | How It Works | Benign lab proof |
|---|---|---|---|
| SQL Injection (SQLi) | Injects malicious SQL into input fields to manipulate DB queries | Attacker modifies query to extract or manipulate data | SELECT * FROM users WHERE id='1' OR '1'='1' |
| Cross-Site Scripting (XSS) | Injects malicious scripts into web pages | Scripts execute in the victim’s browser | <script>alert('XSS')</script> |
| Cross-Site Request Forgery (CSRF) | Forces users to execute unwanted actions | Exploits authenticated sessions by tricking browser | <img src="http://target/delete?user=1"> |
| Remote Code Execution (RCE) | Executes attacker-controlled code on the server | Input is passed directly to system functions | Return a random marker from a disposable fixture; do not open a shell |
| Directory Traversal | Accesses files outside the web root | Manipulates file paths using ../ | /download?file=../../etc/passwd |
| File Upload Vulnerability | Uploads malicious files to the server | Server allows unsafe file types or paths | Uploading shell.php and accessing it via URL |
| Command Injection | Injects system commands through user input | Input passed unsanitized to shell commands | ping 127.0.0.1; whoami |
| Insecure Deserialization | Executes code by deserializing untrusted input | Malformed serialized objects trigger code execution | Java/PHP object with injected payload |
| Broken Access Control | Bypasses restrictions to access unauthorized data/functions | Direct access to APIs/URLs without proper checks | Accessing /admin without being admin |
| Server-Side Request Forgery (SSRF) | Causes the server to make an unintended request | A server-side fetch accepts an insufficiently constrained URL | Request one owned canary endpoint and correlate application, DNS, and egress logs |