s4n7h0 / xvwa

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
GNU General Public License v3.0
1.69k stars 339 forks source link

More command injection scenarios. #7

Closed stasinopoulos closed 8 years ago

stasinopoulos commented 8 years ago

Hey @s4n7h0, it would be interesting if there were more command injection scenarios (i.e blind command injections, HTTP Headers command injections, code injections etc).

s4n7h0 commented 8 years ago

@stasinopoulos Surely. We have already got a neat tasklist to work on for the next release, and this is surely in the list :) Thanks for your feedback !!