🔥 BOAND Vulnerability Test Site

Logged in as: Guest

Welcome to BOAND Vulnerability Testing Environment

This is a deliberately vulnerable web application designed to test the BOAND exploitation framework. All vulnerabilities are intentionally implemented for security research and testing purposes.

⚠️ WARNING: This application is EXTREMELY vulnerable. Only deploy on isolated test environments!

🎯 SQL Injection

Test blind, time-based, and union-based SQL injection vulnerabilities with data extraction capabilities.

💉 XSS Vulnerabilities

Reflected, stored, and DOM-based XSS testing with cookie theft and session hijacking.

🔄 CSRF Attacks

Cross-site request forgery with missing token validation and weak protection mechanisms.

🌐 SSRF Testing

Server-side request forgery for internal network pivoting and cloud metadata access.

📄 XXE Injection

XML external entity injection for file disclosure and SSRF chaining.

💻 Command Injection

OS command injection with reverse shell deployment capabilities.

📁 Directory Traversal

Path traversal vulnerabilities with encoding bypass techniques.

📤 File Upload

Unrestricted file upload with web shell deployment testing.

🔑 IDOR

Insecure direct object references for privilege escalation testing.

🎫 JWT Manipulation

JWT token vulnerabilities including algorithm confusion and signature bypass.

🎨 SSTI

Server-side template injection for code execution testing.

🗄️ NoSQL Injection

NoSQL and LDAP injection for database enumeration and data extraction.