
simple-maven
Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45105 with documented exploitation steps and mitigation guidance for security…

Vulnerable Spring Boot web application demonstrating Log4j2 JNDI injection (CVE-2021-44228) with exploitation steps and mitigation guidance for…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

Reproduction environment for CVE-2025-29927, demonstrating Next.js middleware authorization bypass via the x-middleware-subrequest header. Includes…

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

CTF challenge container with a Next.JS middleware vulnerability (CVE-2025-29927) for practicing man-in-the-middle attacks and API exploitation.

Demonstrates the x-middleware-subrequest header bypass in Next.js 13.4.19, allowing unauthorized access to protected routes. Includes setup, normal…

Test and validate Log4Shell (CVE-2021-44228) mitigation approaches with a sample vulnerable Log4j app, including JNDI exploitation, environment…

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

Deliberately vulnerable web application portal with a containerized backend, designed for practicing exploitation of CVE-2021-44228 and container…

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

Deliberately vulnerable Apache Solr application (CVE-2021-44228) for practicing Log4Shell exploitation via User-Agent, POST, and admin endpoints.…

Insecure Java Deserialization Lab