
  1. Username Enumeration: Green Website. The developer set the text "Login in was unsuccessful" to bold for an existing user but did not for a user that did not exist.
  2. Insecure Direct Object Reference: Red. The other two sites probably checked if the current user had access to view data on certain salespeople.
  3. SQL Injection: Blue.
  4. Cross-site Scripting: Green.
  5. Cross-Site Request Forgery: Red.
  6. Session Hijacking/Fixation: Blue.

GIF Here: Video Walkthrough

For CSRF: Video Walkthrough

Bonus Objective 2a: Video Walkthrough