KO
|
EN
gitlite — search
Search
#typescript
#ai-agents
#deepseek-harness
#dsh-plugin
#open-source
#ai
#claude-code
#cli
#windows
#codex
#developer-tools
#dsh
ninjasworkout
★ 97
Open GitHub ↗
Vulnerable NodeJS Web Application
Download README (.md)
Explore Similar Repositories
skywalking-cli
:
Apache SkyWalking CLI
eleventy-plugin-prismic
:
Eleventy plugin and shortcodes to fetch and present Prismic content
jwt-node-vue
:
Repositório responsável pelo primeiro projeto da série de vídeos: Coding Stuff.
superdiary
:
Kotlin/Compose Multiplatform Diary App with shared UI (Android, iOS, Desktop, Web)
bitflags
:
Single-header header-only C++11 / C++14 / C++17 library for easily managing set of auto-generated type-safe flags.
// repository documentation
Was this content helpful?
★ 0
(0 ratings)
Select Rating:
★
★
★
★
★
Submit Feedback
Recent Feedback
×
Download README
Do you want to download the
README.md
file for
ninjasworkout
?
Download (.md)
# Damn Vulnerable NodeJS Application ## Quick Start ``` Download the Repo => run npm i ``` Afer Installing all dependency just run the application ``` node app.js or nodemon app.js ```  ## ADDED BUGS - Prototype Pollution ✅1 - No SQL Injection ✅2 - Cross site Scripting ✅3 - Broken Access Control ✅4 - Broken Session Management ✅5 - Weak Regex Implementation ✅ 6 - Race Condition ✅7 - CSRF -Cross Site Request Forgery ✅8 - Weak Bruteforce Protection ✅9 - User Enumeration ✅10 - Reset Password token leaking in Referrer ✅11 - Reset Password bugs ✅12 - Sensitive Data Exposure ✅13 - Unicode Case Mapping Collision ✅14 - File Upload ✅ 15 - SSRF ✅ 16 - XXE - Open Redirection ✅ 17 - Directory Traversal ✅ 18 - Insecure Deserilization => Remote Code Execution ✅ 19 - Server Side Template Injection 🚶♂️🚶♂️🚶 - Timing Attack 🚶♂️🚶♂️🚶 ⚠️⚠️ Reset Password Module will not work !! You have to configure SMTP !! in utils=>sendmail.js⚠️⚠️ # TODO - Improvement in User Interface - Add New Vulnerabilities on weekly basis - Add Documentation of all the Vulnerabilites # Issues - In case of bugs in the application, feel free to create an [issues](https://github.com/effortlessdevsec/ninjasworkout/issues) on github. # Contribution - Feel free to create a pull request for any contribution.