Bug Bounty Course Content
Bug Bounty Course Content
Bug Bounty Course Content
2020
Priority OWASP Top Ten + Bugcrowd Extras Specific Vulnerability Name Variant or Affected Function
P1
Server Security Misconfiguration Using Default Credentials
Server-Side Injection File Inclusion Local
Server-Side Injection Remote Code Execution (RCE)
P2
Server Security Misconfiguration Misconfigured DNS High Impact Sub domain Takeover
Server Security Misconfiguration OAuth Misconfiguration Account Takeover
Broken Authentication and Session Management Second Factor Authentication (2FA) Bypass
Broken Authentication and Session Management Weak Login Function HTTPS not Available or HTTP by Default
Broken Authentication and Session Management Session Fixation Remote Attack Vector
Sensitive Data Exposure EXIF Geolocation Data Not Stripped From Uploaded Images Automatic User Enumeration
Cross-Site Scripting (XSS) Stored Privileged User to Privilege Elevation
Priority OWASP Top Ten + Bugcrowd Extras Specific Vulnerability Name Variant or Affected Function
Server Security Misconfiguration Missing Secure or HTTPOnly Cookie Flag Session Token
Broken Authentication and Session Management Failure to Invalidate Session On Password Reset and/or Change
Broken Authentication and Session Management Weak Registration Implementation Over HTTP
Sensitive Data Exposure EXIF Geolocation Data Not Stripped From Uploaded Images Manual User Enumeration
Sensitive Data Exposure Visible Detailed Error/Debug Page Detailed Server Configuration
Priority OWASP Top Ten + Bugcrowd Extras Specific Vulnerability Name Variant or Affected Function
Sensitive Data Exposure Token Leakage via Referer Untrusted 3rd Party
User Facing
Sensitive Data Exposure Weak Password Reset Implementation Password Reset Token Sent Over HTTP
Server Security Misconfiguration Misconfigured DNS Missing Certification Authority Authorization (CAA) Record
Server Security Misconfiguration Mail Server Misconfiguration Email Spoofing to Spam Folder
Server Security Misconfiguration Mail Server Misconfiguration Missing or Misconfigured SPF and/or DKIM
P5
CONTINUED
Server Security Misconfiguration
Server Security Misconfiguration
Unsafe File Upload
Unsafe File Upload
No Size Limit
File Extension Filter Bypass
Server Security Misconfiguration Cookie Scoped to Parent Domain
Server Security Misconfiguration Missing Secure or HTTPOnly Cookie Flag Non-Session Cookie
Server Security Misconfiguration Clickjacking Form Input
Server Security Misconfiguration Clickjacking Non-Sensitive Action
Server Security Misconfiguration CAPTCHA Brute Force