web2-vuln-classes

Summarize 18 web2 vulnerability classes with detection patterns and examples.

2|1|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill web2-vuln-classes-mikacr1138
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web2-vuln-classes
Source: https://github.com/Mikacr1138/claude-bug-bounty/tree/main/skills/web2-vuln-classes
Command: npx skills add https://github.com/Mikacr1138/claude-bug-bounty --skill web2-vuln-classes-mikacr1138

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This knowledge base consolidates root causes, detection patterns, bypass techniques, and real-world examples for 18 web2 vulnerability classes, helping security teams study, compare, and hunt more effectively.

Core Features & Use Cases

  • Comprehensive coverage of 18 web2 bug classes including IDOR, broken authentication/authorization, XSS, SSRF, SQL injection, OAuth/OIDC issues, file upload bypass techniques, GraphQL, and cloud/infra misconfigurations.
  • Provides root causes, detection patterns, bypass tables, exploit techniques, and real-world paid examples to accelerate triage and research.
  • Use Case: security researchers can quickly identify relevant class patterns for a target, reproduce attacker techniques in a controlled environment, and prioritize mitigations.

Quick Start

Describe a chosen web2 vulnerability class and generate a structured report with root causes, detection patterns, and real-world examples.

Frequently Asked Questions about web2-vuln-classes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the root causes of common web2 vulnerability classes like XSS and SSRF?

Web2 vulnerability classes like XSS and SSRF stem from improper input validation and insecure URL fetching. This reference details root causes, detection patterns, and bypass techniques for 18 classes including SQLi, IDOR, and OAuth issues.

How do I detect and bypass IDOR and broken authentication in web applications?

To detect IDOR and broken authentication, manipulate object references and test session validation flaws. This guide provides structured detection patterns, bypass tables, and real-world paid examples to accelerate your bug bounty triage and research.

Does this cover specific attack patterns for GraphQL and OAuth/OIDC misconfigurations?

Yes, it covers attack patterns for GraphQL and OAuth/OIDC misconfigurations. The knowledge base summarizes 18 web2 bug classes including file upload bypasses, SSTI, subdomain takeover, and cloud misconfigurations with practical exploit examples.

What is the best way to study web2 bug bounty classes for security research?

The best way to study web2 bug bounty classes is reviewing structured reports of root causes and real-world examples. This reference streamlines study and hunt workflows by consolidating detection patterns and exploit techniques for 18 distinct vulnerability classes.

When should I use a structured vulnerability reference for cloud misconfig and SSTI hunting?

Use a structured vulnerability reference for cloud misconfig and SSTI hunting when you need to quickly identify target patterns and reproduce attacker techniques. It provides structured content delivery covering root causes and guidance for prioritizing mitigations.