Skip to content
Open access

Security analysis of selected web applications using vulnerability scanners

Sep 2026 · Journal of Computer Sciences Institute · 0 citations · 9 references

Abstract

Web applications are among the most frequently targeted systems in today’s cyber-threat landscape, and vulnerabilities such as SQL injection, cross-site scripting and various configuration errors have dominated the OWASP Top 10 list for years. This article examines the security of a web application using modern vulnerability scanning tools and penetration testing. The study was conducted in two stages: in the first stage, the deliberately vulnerable OWASP Juice Shop application was used, with three scanners: OWASP ZAP, Burp Suite Community Edition and Nuclei applied to it. In the second stage, the tools were used to assess the security of a proprietary web application. All tests were conducted in a local, controlled environment and utilised Docker containerisation for the deliberately vulnerable application. The results of the proprietary application assessment revealed no logical vulnerabilities from the OWASP Top 10 category. The tools did not confirm the presence of SQL Injection, XSS or Broken Access Control. The identified issues related solely to the configuration of HTTP security headers. The study confirms that none of the scanners used can detect the full spectrum of vulnerabilities on their own, and that a combination of automated, semi-automated and template-based scanning provides the most comprehensive assessment of web application security.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.