web2-vuln-classes

Organize recon findings into 18 web2 vulnerability classes with detection patterns.

1|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/zer0xhamid/LogicHunter_v2 --skill web2-vuln-classes-zer0xhamid
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web2-vuln-classes
Source: https://github.com/zer0xhamid/LogicHunter_v2/tree/main/skills/web2-vuln-classes
Command: npx skills add https://github.com/zer0xhamid/LogicHunter_v2 --skill web2-vuln-classes-zer0xhamid

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Complete reference for 18 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. It provides a consolidated taxonomy to help security researchers quickly classify recon findings and study attack surfaces.

Core Features & Use Cases

  • Comprehensive taxonomy for IDOR, Broken Auth, XSS, SSRF, SQLi, OAuth/OIDC, file upload bypass techniques, GraphQL, LLM/AI risks, API misconfig, ATO, SSTI, subdomain takeover, cloud misconfigs, HTTP smuggling, and cache poisoning.
  • Practical guidance with root causes, detection patterns, bypass techniques, chaining opportunities, and real-world paid examples to illustrate impact.
  • Use cases include rapid study, recon classification, and reference during bug-hunting planning.

Quick Start

Select a web2 bug class from the list and review its root cause, detection patterns, and real-world examples to inform your testing plan.

Frequently Asked Questions about web2-vuln-classes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the most common web2 vulnerability classes for bug bounty research?

Common web2 vulnerability classes include IDOR, XSS, SSRF, SQLi, and OAuth misconfigurations. A comprehensive taxonomy maps 18 distinct web2 bug classes with root causes, detection patterns, and real paid examples to accelerate security testing.

How do I classify recon findings against web2 vulnerability classes?

To classify recon findings, map discovered attack surfaces to 18 web2 vulnerability classes. Review the specific root causes and detection patterns for each class to systematically identify and categorize potential security issues during bug hunting.

Does this taxonomy cover modern API and GraphQL vulnerability detection patterns?

Yes, the taxonomy covers API misconfigurations and GraphQL vulnerabilities. It includes detection patterns, root causes, and bypass techniques for these modern web2 attack surfaces alongside traditional classes like SQLi and broken authentication.

What bypass techniques exist for file upload vulnerabilities in web2 applications?

File upload bypass techniques are documented as part of the 18 web2 vulnerability classes. The taxonomy provides practical guidance on root causes, specific bypass methods, chaining opportunities, and real-world paid examples to illustrate exploit impact.

Can I use this taxonomy to study LLM and AI risks in web2 environments?

Yes, LLM and AI risks are included as a specific web2 vulnerability class. The reference provides root causes, detection patterns, and real-world examples to help security researchers study and test AI-integrated attack surfaces.

How do I chain web2 vulnerabilities like HTTP smuggling and cache poisoning?

The taxonomy details chaining opportunities for vulnerabilities like HTTP smuggling and cache poisoning. By reviewing root causes and detection patterns, researchers can identify how to combine these web2 exploit techniques for greater impact.