BTS Lab is an open source vulnerable web application. It can be used to learn about many different types of web application vulnerabilities.

Currently, the app allows you to learn the following vulnerability types:
  • SQL Injection
  • XSS(includes Flash Based xss)
  • CSRF
  • Clickjacking
  • SSRF
  • File Inclusion
  • Code Execution
  • Insecure Direct Object Reference
  • Unrestricted File Upload vulnerability
  • Open URL Redirection
  • Server Side Includes(SSI) Injection

-------------
Admin Credentials:
Username: admin
Password : password

Go to Admin Page >>

Copyrights © Cyber Security & Privacy Foundation