Click on any module to practice exploiting the vulnerability. Use Burp Suite to intercept and modify requests.
Vulnerable login form with raw SQL queries. Bypass authentication or extract data.
Critical Practice →Search functionality that reflects user input directly without sanitization.
High Practice →Comment section storing malicious scripts in the database permanently.
Critical Practice →Network diagnostic tool executing system commands without validation.
Critical Practice →Unrestricted file upload allowing execution of malicious PHP files.
Critical Practice →File viewer vulnerable to path traversal attacks (../ sequences).
High Practice →Weak login logic and session validation that can be bypassed.
Critical Practice →Profile page allowing unauthorized access to other users' data.
High Practice →E-commerce checkout with client-side price/quantity validation only.
High Practice →