Security Misconfiguration (OWASP A05)
Missing or improperly configured security controls at any level of the application stack.
Skills
- XXE - XML External Entity injection
- File Upload - Unrestricted file upload exploitation
- Subdomain Takeover - Dangling DNS exploitation
- Cache Deception - Web cache poisoning attacks
Quick Reference
| Attack | Target | Impact |
|---|---|---|
| XXE | XML parsers | File read, SSRF, RCE |
| File Upload | Upload endpoints | Webshell, RCE |
| Subdomain Takeover | Dangling DNS | Phishing, cookies |
| Cache Deception | CDN/proxy | Data theft |
Converted and distributed by TomeVault — claim your Tome and manage your conversions.