VULNERABILITIES
Gin & Juice Shop is packed with vulnerabilities, ready to put any web vulnerability scanner to the test. To help you evaluate, we've also listed notable difficulties and technologies.
ACCOUNT LOGIN DETAILS
Username | c a r l o s | Password | h u n t e r 2 |
---|
Path | Difficulties | Technologies | Vulnerabilities |
---|---|---|---|
/ | JavaScript event handlers JavaScript modifies request | JavaScript | Base64-encoded data in parameter Request URL override |
/ a b o u t | |||
/ b l o g | Client-side prototype pollution Client-side template injection Cross-site scripting (DOM-based) Open redirection (DOM-based) | ||
/ b l o g / p o s t | |||
/ c a t a l o g | Client-side template injection Cross-site scripting (reflected) DOM data manipulation (reflected DOM-based) HTTP response header injection Link manipulation (reflected DOM-based) SQL injection | ||
/ c a t a l o g / c a r t | |||
/ c a t a l o g / p r o d u c t | |||
/ c a t a l o g / p r o d u c t / s t o c k | JavaScript event handlers JavaScript modifies request JavaScript client side rendering | JavaScript | XML external entity injection |
/ c a t a l o g / s u b s c r i b e | Cross-site scripting (reflected) | ||
/ i m a g e / s c a n m e / b l o g / p o s t s / 1 . j p g | |||
/ i m a g e / s c a n m e / b l o g / p o s t s / 2 . j p g | |||
/ i m a g e / s c a n m e / b l o g / p o s t s / 3 . j p g | |||
/ i m a g e / s c a n m e / b l o g / p o s t s / 4 . j p g | |||
/ i m a g e / s c a n m e / b l o g / p o s t s / 5 . j p g | |||
/ i m a g e / s c a n m e / b l o g / p o s t s / 6 . j p g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 1 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 1 0 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 1 1 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 1 2 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 2 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 3 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 4 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 5 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 6 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 7 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 8 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / 9 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / b a t c h _ 1 3 3 7 . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / k e t t l e _ s t i l l . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / l o s t _ i n _ a _ h e y e s . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / o r i g i n a l _ d r y _ s q l i . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / p i n e a p p l e _ e d i t i o n . p n g | |||
/ i m a g e / s c a n m e / p r o d u c t c a t a l o g / p r o d u c t s / p u r p l e _ h a t . p n g | |||
/ l o g g e r | |||
/ l o g i n | Cross-site scripting (reflected) DOM data manipulation (reflected DOM-based) | ||
/ m y - a c c o u n t | |||
/ r e s o u r c e s / c s s / l a b s B l o g . c s s | |||
/ r e s o u r c e s / c s s / l a b s E c o m m e r c e . c s s | |||
/ r e s o u r c e s / c s s / l a b s S c a n m e . c s s | |||
/ r e s o u r c e s / f o n t s / J o s e f i n S a n s / J o s e f i n S a n s - B o l d . w o f f | |||
/ r e s o u r c e s / f o n t s / P o p p i n s / p o p p i n s - b o l d . w o f f | |||
/ r e s o u r c e s / f o n t s / P o p p i n s / p o p p i n s . w o f f | |||
/ r e s o u r c e s / f o o t e r / j s / s c a n m e . j s | |||
/ r e s o u r c e s / i m a g e s / P o r t s w i g g e r . p n g | |||
/ r e s o u r c e s / i m a g e s / a v a t a r . s v g | |||
/ r e s o u r c e s / i m a g e s / b a t c h 1 3 3 7 _ c a n . p n g | |||
/ r e s o u r c e s / i m a g e s / c h e c k - c i r c l e . s v g | |||
/ r e s o u r c e s / i m a g e s / c l o s e - b u t t o n . s v g | |||
/ r e s o u r c e s / i m a g e s / c o p y - t o - c l i p b o a r d . s v g | |||
/ r e s o u r c e s / i m a g e s / d a r k - b l u e - s q u i g g l e - p a t t e r n - t i l e . j p g | |||
/ r e s o u r c e s / i m a g e s / d r y _ S Q L I _ c a n . p n g | |||
/ r e s o u r c e s / i m a g e s / f o o t e r _ g r a p h i c . j p g | |||
/ r e s o u r c e s / i m a g e s / g _ j _ b o t t l e . p n g | |||
/ r e s o u r c e s / i m a g e s / g i n - a n d - j u i c e - d i s t i l l e r y . j p g | |||
/ r e s o u r c e s / i m a g e s / g i n - a n d - j u i c e - s h o p - l o g o - s m a l l . s v g | |||
/ r e s o u r c e s / i m a g e s / g i n - a n d - j u i c e - s h o p - l o g o . s v g | |||
/ r e s o u r c e s / i m a g e s / g i n - a n d - j u i c e - t e a m . j p g | |||
/ r e s o u r c e s / i m a g e s / g i n - a n d - j u i c e - t e a m . m p 4 | |||
/ r e s o u r c e s / i m a g e s / g o g g l e s . s v g | |||
/ r e s o u r c e s / i m a g e s / h e r o _ b a n n e r _ b a c k g r o u n d 1 . j p g | |||
/ r e s o u r c e s / i m a g e s / h e r o _ b a n n e r _ b a c k g r o u n d 2 . p n g | |||
/ r e s o u r c e s / i m a g e s / h e y e s _ b o t t l e . p n g | |||
/ r e s o u r c e s / i m a g e s / i c o n - a c c o u n t . s v g | |||
/ r e s o u r c e s / i m a g e s / i c o n - c a r t . s v g | |||
/ r e s o u r c e s / i m a g e s / i c o n - s e a r c h . s v g | |||
/ r e s o u r c e s / i m a g e s / k e t t l e _ b o t t l e . p n g | |||
/ r e s o u r c e s / i m a g e s / n o t - f o u n d . s v g | |||
/ r e s o u r c e s / i m a g e s / p i n e a p p l e - c a n . p n g | |||
/ r e s o u r c e s / i m a g e s / r a t i n g 1 . p n g | |||
/ r e s o u r c e s / i m a g e s / r a t i n g 2 . p n g | |||
/ r e s o u r c e s / i m a g e s / r a t i n g 3 . p n g | |||
/ r e s o u r c e s / i m a g e s / r a t i n g 4 . p n g | |||
/ r e s o u r c e s / i m a g e s / r a t i n g 5 . p n g | |||
/ r e s o u r c e s / i m a g e s / s h o p p i n g - c a r t . s v g | |||
/ r e s o u r c e s / i m a g e s / t r a c k e r . g i f | |||
/ r e s o u r c e s / j s / a n g u l a r _ 1 - 7 - 7 . j s | Vulnerable JavaScript dependency | ||
/ r e s o u r c e s / j s / d e p a r a m . j s | |||
/ r e s o u r c e s / j s / r e a c t - d o m . d e v e l o p m e n t . j s | |||
/ r e s o u r c e s / j s / r e a c t . d e v e l o p m e n t . j s | |||
/ r e s o u r c e s / j s / s e a r c h L o g g e r . j s | |||
/ r e s o u r c e s / j s / s t o c k C h e c k . j s | |||
/ r e s o u r c e s / j s / s u b s c r i b e N o w . j s | |||
/ r e s o u r c e s / j s / x m l S t o c k C h e c k P a y l o a d . j s | |||
/ r e s o u r c e s / l a b h e a d e r / c s s / s c a n M e H e a d e r . c s s | |||
/ r o b o t s . t x t |