Xtreme Vulnerable Web Application: a badly coded PHP/MySQL coffee shop with one module per web vulnerability, from SQL injection and XPath injection to PHP object injection, SSRF and server-side template injection.
Not startedDockercommit 0795daex86_64 · aarch64Secret
Exploit each XVWA module, starting with SQL injection.
The brief for this lab lives in its repository.