Hands-on web application security exercises and vulnerability walkthroughs.
User-controlled search input is reflected without sanitization, allowing arbitrary JavaScript execution.