This project is a vulnerable Symfony application intended to be used for security training purposes.
858
Caution
This application is intended to be vulnerable. Do not deploy it in a public environment.
This project is a vulnerable Symfony application intended to be used for security training purposes.
You can deploy the application on your machine with following command:
docker run -d --name vulnerablesymfony -p 8000:80 secureaks/vulnerablesymfony:latest
The application will be available at http://localhost:8000.
You can get further details on our GitHub repository: https://github.com/Secureaks/VulnerableSymfony
You can find below the list of vulnerabilities available in the application. The source code available on the GitHub repository is also documented to allow you to understand how the vulnerabilities are implemented.
/ and /post/{post}/post/{post}/comment/searchp parameter on legal/contentemail parameter on /login/register/user/role/{user}/user/delete/{user}/user/password/{user}/user/email/{user}/user/avatar/{user}url parameter on /user/avatar/url/{user}/user/avatar/delete/{user}/user/avatar/resize/{user}/user/about/local/info.phpOptions +Indexes on the vhost configuration/user/edit/ leading to privilege escalationThis project is provided by Secureaks.
If you want to contribute to this project, fill free to open an issue or a pull request with your changes.
This project is licensed under the ATTRIBUTION-NONCOMMERCIAL-SHAREALIKE 4.0 INTERNATIONAL (CC BY-NC-SA 4.0) license.
You are free to:
The licensor cannot revoke these freedoms as long as you follow the license terms.
Under the following terms:
No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.
See the LICENSE file on the Github repository for details.
Content type
Image
Digest
sha256:8c48148d0…
Size
282.8 MB
Last updated
over 1 year ago
docker pull secureaks/vulnerablesymfony