> For the complete documentation index, see [llms.txt](https://htb.linuxsec.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://htb.linuxsec.org/web-application.md).

# Web Application

- [Common Applications](https://htb.linuxsec.org/web-application/common-applications.md): Attacking Common Applications
- [Tomcat](https://htb.linuxsec.org/web-application/common-applications/tomcat.md): Attacking Tomcat Service
- [Joomla](https://htb.linuxsec.org/web-application/common-applications/joomla.md): Attacking Joomla CMS
- [SSTI](https://htb.linuxsec.org/web-application/ssti.md): Notes about some basic Server Side Template Injection attack
- [File Inclusion](https://htb.linuxsec.org/web-application/file-inclusion.md): Notes about some basic File Insclusion attack
- [XSS](https://htb.linuxsec.org/web-application/xss.md): Cross-site scripting cheat sheet
- [Misc](https://htb.linuxsec.org/web-application/misc.md): Other useful stuff about Web Pentesting
