WebVerse Writeups
  • Home
  • Foundational Labs
  • Labs
  • Challenges
  • Hack on WebVerse →

WebVerse

Canal Cove Books

The owner watched a tutorial on XSS and wrote two regexes. Two.

By Minatour 28 Apr 2026

WebVerse

Breach

Breach's team collaboration platform. Some content is restricted to admins — but is the enforcement as tight as it looks?

By Minatour 28 Apr 2026

WebVerse

Banyan

A community-garden app strips event handlers after a space. Only after a space.

By Minatour 28 Apr 2026

WebVerse

Sprocket Line

A bike-parts shop paid good money for a filter that strips 'script'. Only that.

By Minatour 28 Apr 2026

WebVerse

Palisade

Mountaineering rental site. Their filter has a case.

By Minatour 28 Apr 2026

WebVerse

Proxy Pursuit

LoadMesh's ops console shows live connection telemetry. Behind the login, one of the pages trusts a header the user fully controls. Login with admin / admin. The injection is not on any form.

By Minatour 28 Apr 2026

WebVerse

Herbalist Remedies

Herbalist Remedies — an herbal-blend catalog — trusts its login form to compare MongoDB query objects. Slip an operator in and see who else is home.

By Minatour 26 Apr 2026

WebVerse

Trace Control

Trackboard, an internal issue tracker, rolled to production with display_errors accidentally left on. Its /issues page has a numeric id param and a loose sense of type safety. Coax a database error to tell you what you need.

By Minatour 26 Apr 2026

WebVerse

SwiftSearch Hotels

SwiftSearch's hotel API accepts a JSON filter body that's merged straight into a MongoDB-style query. Ordinary users filter by city and price; operators slip in just as easily.

By Minatour 26 Apr 2026

WebVerse

Voucher Vault

Redzone Rewards — an internal employee rewards portal — exposes a voucher search that concatenates user input straight into a SELECT. Find the hidden administrative voucher.

By Minatour 26 Apr 2026

WebVerse

Ember Kettle

A small tea shop's brand-new online catalog has a search bar that trusts everything you give it. No filter, no escape, no second thoughts.

By Minatour 26 Apr 2026

WebVerse

Shadow Registrar

RegistryPro's WHOIS terminal returns three things: a status word, a reflected domain name, and a lookup time. The query layer accepts stacked statements. Everything you need leaks through the clock.

By Minatour 26 Apr 2026
See all
WebVerse Writeups
  • RSS
  • WebVerse Pro
  • LinkedIn
  • YouTube
  • GitHub
Powered by Ghost