Injectics
Initial enumeration
Zed Attack Proxy (ZAP)

Basic fuzzing:

Source code review

Exploring the application
(1) Normal user login
Further testing
(2) Edit leader board
SSTI injection on the admin profile page
Twig SSTI injection
Identifying vulnerability to SSTI
Last updated