Ceyhun Hacıbəyli küçəsi 100, AZ1007

Exploits the browser's default behavior of automatically including session cookies with cross-site requests.

XSS occurs when an application includes untrusted data in a web page without proper validation. WEB-200 teaches you how to leverage XSS to steal session tokens, build phishing pages, or perform actions on behalf of other users. You will learn to bypass basic signature filters by using alternative JavaScript execution contexts. 2. SQL Injection (SQLi)

Critical directives ( Host , X-Forwarded-For , Authorization ) that control application logic. Enumeration Techniques