![Practical Web Penetration Testing](https://wfqqreader-1252317822.image.myqcloud.com/cover/769/36699769/b_36699769.jpg)
OWASP Top 10
The Open Web Application Security Project (OWASP) is a community dedicated to helping people and organizations with application security topics. If you'll be working as an AppSec expert, then OWASP should be your bible; they have plenty of help sections that will make your life much easier. Just follow their guidelines and tutorials at http://www.owasp.org.
The OWASP community defined the Top 10 vulnerabilities related to web applications. As for Mutillidae, it dedicated a menu to these vulnerabilities. On the left menu, you will see the OWASP items organized by year (the latest is the OWASP Top 10 for 2017; see the following screenshot). OWASP always keeps this list updated with the latest web vulnerabilities:
![](https://epubservercos.yuewen.com/97ABE4/19470392301559806/epubprivate/OEBPS/Images/Chapter_74.jpg?sign=1738819938-4mjSFGb8DtKpPe0rG6fbWWokvlxzyFFi-0-c3d67fd1df85648b6e0d27a71ae1db71)
I have dedicated a whole chapter to these vulnerabilities, later in this book. For the time being, try to get familiar with the menu items.