Vulnerability
Lab
Master 10 critical web vulnerabilities through hands-on simulation. Each module teaches the attack vector and the corresponding defense.
SQL Injection
Inject malicious SQL queries through input fields to manipulate backend databases.
XSS
Inject malicious scripts into web pages viewed by other users.
CSRF
Trick authenticated users into executing unwanted actions.
Path Traversal
Manipulate file paths to access restricted directories.
Command Injection
Execute arbitrary system commands through vulnerable inputs.
IDOR
Access unauthorized resources by manipulating object references.
SSRF
Trick the server into making requests to internal resources.
File Upload
Upload malicious files to gain remote code execution.
RCE
Exploit deserialization flaws for arbitrary code execution.
XXE
Exploit XML parsers to read internal files or cause DoS.
Click any module card to mark it as completed. Progress is saved locally.