Intentionally vulnerable web application: SQL Injection + RCE + Privilege Escalation
2.8K
This image only runs on x86-64 systems, not on ARM (like Apple Silicon).

This is free vulnerable app for pentesters / cybersecurity students / developers to experiment with SQL Injection vulnerability and privilege escalation.
You will find a detailed description here: https://www.karczewski.io/blog/intentionally-vulnerable-web-application-sql-injection-rce-privilege-escalation/
Recommended path:
1. exploit the SQLi vulnerability
2. get shell via vulnerable version of PostgreSQL
3. perform privilage escalation and become root
Have fun :)
docker run -p 8091:80 -d filipkarc/sqli-postgres-rce-privesc-hacking-playground
Then launch your browser and enter http://localhost:8091
This application is intentionally INSECURE and is meant solely for demonstrating security risks in a controlled environment. It should never be exposed to public networks or production systems. Running this application outside of isolated labs may result in unauthorized access or system compromise. Usage is at the user's own risk.
LinkedIn: https://www.linkedin.com/in/filip-karczewski/
Twitter: https://twitter.com/karczewski_io
Thanks to the creator of the photo I used:
https://www.pexels.com/photo/cute-puppy-wearing-a-party-hat-4588047/
Content type
Image
Digest
sha256:80f5879ba…
Size
145.8 MB
Last updated
about 1 year ago
docker pull filipkarc/sqli-postgres-rce-privesc-hacking-playground