Security analysis of selected web applications using vulnerability scanners

Main Article Content

Mariusz Choroś

s95376@pollub.edu.pl

https://orcid.org/0009-0004-8747-3448
Marta Dziuba-Kozieł

m.dziuba@pollub.pl

Abstract

Web applications are among the most frequently targeted systems in today’s cyber-threat landscape, and vulnerabilities such as SQL injection, cross-site scripting and various configuration errors have dominated the OWASP Top 10 list for years. This article examines the security of a web application using modern vulnerability scanning tools and penetration testing. The study was conducted in two stages: in the first stage, the deliberately vulnerable OWASP Juice Shop application was used, with three scanners: OWASP ZAP, Burp Suite Community Edition and Nuclei applied to it. In the second stage, the tools were used to assess the security of a proprietary web application. All tests were conducted in a local, controlled environment and utilised Docker containerisation for the deliberately vulnerable application. The results of the proprietary application assessment revealed no logical vulnerabilities from the OWASP Top 10 category. The tools did not confirm the presence of SQL Injection, XSS or Broken Access Control. The identified issues related solely to the configuration of HTTP security headers. The study confirms that none of the scanners used can detect the full spectrum of vulnerabilities on their own, and that a combination of automated, semi-automated and template-based scanning provides the most comprehensive assessment of web application security.

Keywords:

owasp zap, web application security, vulnerability scanner, Burp Suite, Nuclei, penetration testing

Sustainable Development Goal (SDG)

  • Industry, Innovation, Technology and Infrastructure
  • Peace, justice and strong institutions

References

Article Details

Choroś, M., & Dziuba-Kozieł, M. (2026). Security analysis of selected web applications using vulnerability scanners . Journal of Computer Sciences Institute, 40, 206-212. https://doi.org/10.35784/jcsi.9596