Skip to content

hkm67/vuln-note

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

vuln-note

An intentionally vulnerable note-sharing application for a mini pentest demo.


Vulnerabilities Demostrated:

  • Leaked Internal Documentations containing Credentials (Discovered via Directory Busting)
  • No Account Lockout (Brute-force Login to User with Weak Password)
  • Notes Function vulnerable to XSS
  • Session Hijacking via Extracting Session Token (Insecure Cookie Settings)
  • Code Execution Vulnerability in Check Log Function

About

An intentionally vulnerable note-sharing application for a mini pentest demo.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages