wavsep (original) (raw)

A vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners.

This evaluation platform contains a collection of unique vulnerable web pages that can be used to test the various properties of web application scanners.

Visit WAVSEP homepage to learn more:
https://code.google.com/p/wavsep/

The project includes the following test cases:

Path Traversal/LFI: 816 test cases (GET & POST)
Remote File Inclusion (XSS via RFI): 108 test cases (GET & POST)
Reflected XSS: 66 test cases, implemented in 64 jsp pages (GET & POST)
Error Based SQL Injection: 80 test cases, implemented in 76 jsp pages (GET & POST)
Blind SQL Injection: 46 test cases, implemented in 44 jsp pages (GET & POST)
Time Based SQL Injection: 10 test cases, implemented in 10 jsp pages (GET & POST)

Project Samples

wavsep Screenshot 1

License

GNU General Public License version 3.0 (GPLv3)

Our Free Plans just got better! | Auth0 Icon

Our Free Plans just got better! | Auth0

With up to 25k MAUs and unlimited Okta connections, our Free Plan lets you focus on what you do best—building great apps.

You asked, we delivered! Auth0 is excited to expand our Free and Paid plans to include more options so you can focus on building, deploying, and scaling applications without having to worry about your security. Auth0 now, thank yourself later.

User Reviews

Additional Project Details

Operating Systems

Linux, Windows

Languages

English

Intended Audience

Education, Developers, Quality Engineers, Testers, Security Professionals, Security

User Interface

Web-based

Programming Language

JSP, Java

Database Environment

JDBC, MySQL, Other file-based DBMS

JSP Security Software, JSP Software Testing Tool, JSP Benchmark Software, JSP Vulnerability Scanners, Java Security Software, Java Software Testing Tool, Java Benchmark Software, Java Vulnerability Scanners

2014-01-29