Cylab Play is a collection of vulnerable applications that can be used to illustrate and experiment with different kinds of vulnerabilities.
A web application that can be hacked using SQL injection attack. The app uses a MySQL database and parameters are sent using a GET request.
A web application that can be hacked using SQL injection attack. The app uses a MySQL database.
A web application that can be hacked using SQL injection attack. The app uses nice URL's.
A web application that can be hacked using SQL injection attack. The app uses a SQLite database.
A web application that can be hacked using a brute force attack.
A vulnerable web application suffering from unrestricted file upload
A simple web application, that will reveal a secret code if you query using a command line tool like netcat, telnet or simpletcpclient.