LER.me

Make All Learning Count.

Get it on Google PlayDownload on the App Store

Get Connected

  • What is a LER?
  • FAQs (opens in new tab)
  • Partner with Us
  • Visit EBSCOed (opens in new tab)

View our Policies

  • Accessibility (opens in new tab)
  • Standards (opens in new tab)
  • Terms of Use (opens in new tab)
  • Privacy Policy (opens in new tab)
  • Opt out (opens in new tab)

© 2026 All rights reserved.

Powered by EBSCOed

Skip to main contentSkip to footer
My LER
My LER
  1. Programs
  2. OffSec Web Expert (OSWE)

OffSec Web Expert (OSWE)

Offensive Security

Certification

Become a contributor for free to openly demonstrate student outcomes, industry alignment & eligibility criteria.

The OffSec Web Expert certification demonstrates your ability to identify, exploit, and report on complex vulnerabilities within a real-world environment, culminating in the development of a custom exploit.

Cost

Course + Cert Bundle: $1,749Show moreShow less

Format

Online

Skills & Competencies

Skills developed through this program

  • Understand and exploit stored cross-site scripting (XSS) vulnerabilities
  • Gain insights into SQL injection attacks and develop methods to exploit them
  • Analyze and exploit code injection vulnerabilities in server-side JavaScript
  • Understand deserialization vulnerabilities and learn to exploit them for remote code execution
  • Perform manual source code analysis to identify potential security flaws
  • Develop custom fuzzing tools for vulnerability discovery
Career Pathways

Occupations this program prepares you for

  • Penetration Testers15-1299.04
Program Pathways

Credentials this program stacks toward

No program pathways.

Program Details

Detailed information about this program

Becoming OSWE certified - 48-hour proctored: All exams are proctored by an OffSec employee in a private VPN - Hands-on labs: Identify, exploit, and report real-world vulnerabilities in live lab systems - Compromise multiple machines: You’re required to write a professional report describing your exploitation process for each target - Retrieve proof files: Failure to provide the appropriate documentation or proof files for a specific exam objective may result in partial or zero points being awarded for that objective Train to become OSWE certified WEB-300: Advanced Web Attacks and Exploitation WEB-300 (Advanced Web Attacks and Exploitation) provides experienced offensive cybersecurity team members with a comprehensive analysis of various vulnerabilities and their exploitation techniques in web applications. Building on the PEN-200 and WEB-200 programs, this program will dig deep into the methodologies and skill used to analyze the target web applications and exploit development. This will give learners a complete understanding of the underlying flaws that we are going to exploit. The goal of this course is to expose you to a general and repeatable approach to web application security and vulnerability discovery and exploitation, while continuing to strengthen the foundational knowledge that is necessary when faced with modern-day web applications. WEB-300 covers a wide range of advanced web exploitation skills and techniques, including: - Analyzing and exploiting a deserialization remote code execution (RCE) vulnerability in the DotNetNuke (DNN) platform - Mastering advanced web security methodologies such as fuzzing, static and dynamic analysis, and manual code review - Practicing session hijacking techniques to gain unauthorized access to sensitive data and functionality, including exploiting an RCE vulnerability in the Dolibarr application using a dedicated virtual machine WEB-300 is organized into 17 in-depth modules, each focusing on different topics. Many modules include companion videos and hands-on activities to reinforce the learning experience. Additionally, 20 Challenge Labs are provided to test learners' understanding and prepare them for the OffSec Web Expert (OWSE) certification exam. As an advanced offensive course, WEB-300 is developed to test experienced penetration testers and security professionals seeking to master advanced web application attacks and exploitation techniques. It is expected that learners are not only familiar with basic web technologies and scripting languages, such as JavaScript, PHP, Java, and C#, but also have a high level of experience in offensive techniques taught in PEN-200.

Requirements

What you need to earn this credential

No requirements listed.

Financial Aid

Eligible funding programs

No funding information available.

Scholarships

No scholarships listed.

Visit Program Website
Locations

Where this program is offered

No locations specified.

Student Outcomes

Performance metrics for this program

Completion Rate
Not reported
Placement Rate
Not reported
Related Programs

Programs related to this one

No related programs.