Command Injection - DVWA
Perform command injection using the ping functionality.
Perform command injection using the ping functionality.
Quest: Ensure Access & Identity in Google Cloud
Changing the victim’s password using CSRF.
Trigger an alert pop-up with cookie values using DOM-based XSS.
Read the /etc/passwd file using File Inclusion vulnerability.
Exploit the file upload vulnerability to achieve Remote Code Execution (RCE).
Analyze the JavaScript code to reverse the logic and then submit the word ‘success’ in order to win.
Trigger an alert pop-up with cookie values using Reflected XSS.
Use an SQL injection attack to retrieve the admin password.
Perform a blind SQL injection attack to retrieve the database version.