A deliberately vulnerable Java web application built on Struts 2, Spring, Hibernate and MySQL, with one section per OWASP Top 10 (2013) risk: injection, broken authentication, XSS, IDOR, misconfiguration, sensitive data exposure, missing access control, CSRF, vulnerable components and open redirects.
Pas commencé·Docker·commit ecddeed·x86_64 · aarch64·Secret
Objectif
Exploit each OWASP Top 10 risk the application implements, from SQL and command injection to the vulnerable Struts component.