Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitycredential-access-methoddefault-credential-exposure

Web Application Security Vulnerabilities and Exploitation Techniques

Updated 3mo agoFirst seen Nov 16, 20254 sources

Security researchers and enthusiasts have recently highlighted several web application vulnerabilities and exploitation techniques, focusing on real-world scenarios and educational walkthroughs. One write-up details a web challenge from the v1t CTF, where the key to exploitation was careful source code analysis rather than traditional attack vectors, emphasizing the importance of understanding application logic and default credential checks. Another article provides a step-by-step breakdown of a $6,000 bug bounty awarded for a persistent cross-site scripting (XSS) vulnerability on Yelp.com, explaining how the flaw allowed attackers to hijack user sessions and steal credentials, and offering practical advice for identifying similar bugs.

Additionally, a technical walkthrough demonstrates how reflected XSS can be exploited in the DVWA (Damn Vulnerable Web Application) environment, illustrating the risks of improper input validation and script execution in browsers. A separate analysis explores a Cross-Origin Resource Sharing (CORS) misconfiguration involving a trusted "null" origin, showing how such errors can lead to sensitive data exposure across domains. These cases collectively underscore the ongoing risks posed by web application misconfigurations and the value of both offensive and defensive security research in identifying and mitigating these threats.

Share:
Web Application Security Vulnerabilities and Exploitation Techniques
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Nov 15, 20257mo ago

v1t CTF web challenge story published

An Infosec Writeups article about a v1t CTF web challenge focused on source-code analysis was published. The reference does not indicate a distinct security incident beyond the challenge write-up.

DVWA reflected XSS walkthrough published

An Infosec Writeups walkthrough explaining reflected XSS in DVWA and how user input can trigger script execution was published. The reference appears educational and does not describe a separate real-world incident.

Nov 14, 20257mo ago

Write-up published on $6000 bounty XSS vulnerability

An OSINT Team Blog post breaking down an XSS vulnerability associated with a $6000 bounty was published. No further real-world disclosure or remediation details are provided in the reference.

Nov 13, 20257mo ago

Write-up published on CORS vulnerability involving trusted null origin

An Infosec Writeups article describing a CORS vulnerability with a trusted null origin was published. The reference provides no additional incident details beyond the topic.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
Yelp
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.