RewardNest 9.1 — Deliberately Vulnerable Dezhkav Target
Authorized scanner testing only. All data in these routes is synthetic.

Vulnerability catalog

Injection

SQLi numeric/string/auth/error/union, Boolean blind, time blind, second-order SQLi, NoSQL injection, LDAP injection, bounded command oracle

Browser

Reflected/stored/DOM XSS, global XSS through lab_banner, clickjacking, missing headers, JSONP injection

Access control

IDOR, BOLA, excessive data exposure, mass assignment, unsigned JWT, predictable reset tokens

Server side

Bounded SSRF with public OAST support, XXE against synthetic secrets, path traversal, unrestricted file upload, SSTI

Business logic

CSRF-disabled transfer, race-prone balance update, no rate limit, weak/default credentials

Infrastructure

Host-header reset poisoning, cache poisoning oracle, permissive credentialed CORS, debug/config disclosure

Scanner discovery sitemap · OpenAPI target list

Global reflected-XSS probe: append ?lab_banner=<svg/onload=alert(1)> to almost any HTML page.

DEZHKAV AUTHORIZED VULNERABLE TARGET Open vulnerability catalog