Skip to main content
Interactive Lab Environment

Vulnerability
Lab

Master 10 critical web vulnerabilities through hands-on simulation. Each module teaches the attack vector and the corresponding defense.

track_changesLab Progress
0/10 modules
0%50%100%
databasesql-injection
CRITICAL

SQL Injection

Inject malicious SQL queries through input fields to manipulate backend databases.

MITRET1190Injection
codexss
CRITICAL

XSS

Inject malicious scripts into web pages viewed by other users.

MITRET1059Injection
sync_altcsrf
HIGH

CSRF

Trick authenticated users into executing unwanted actions.

MITRET1204Authentication
folder_openpath-traversal
HIGH

Path Traversal

Manipulate file paths to access restricted directories.

MITRET1083File Access
terminalcommand-injection
CRITICAL

Command Injection

Execute arbitrary system commands through vulnerable inputs.

MITRET1202Execution
vpn_keyidor
HIGH

IDOR

Access unauthorized resources by manipulating object references.

MITRET1213Access Control
publicssrf
CRITICAL

SSRF

Trick the server into making requests to internal resources.

MITRET1190Server-Side
upload_filefile-upload
CRITICAL

File Upload

Upload malicious files to gain remote code execution.

MITRET1204File Access
bug_reportrce
CRITICAL

RCE

Exploit deserialization flaws for arbitrary code execution.

MITRET1203Execution
data_objectxxe
HIGH

XXE

Exploit XML parsers to read internal files or cause DoS.

MITRET1190Injection
terminalLaunch Full Simulatorarrow_forward

Click any module card to mark it as completed. Progress is saved locally.