Therefore in this work we presented a novel technique to demonstrate the web vulnerabilities through live site and prove that simple configuration and coding changes can ensured highly secured website. Hence we studied various vulnerabilities like Unvalidated Input, Broken Access Control, Broken Authentication and Sessions Management, Insecure Configuration Management, Improper Error Handling, Parameter Modification, Cookie Modification and Directory Traversal. Also methods for detecting those vulnerabilities and successfully implemented security mechanism to all those vulnerabilities to provide protection