DVWA Vulnerability Discovery Capstone
One official submission
This is an assessment, not a practice lesson. Correctness feedback is withheld during the assessment, and the official submission is locked after it is recorded.
Work only against the facilitator-configured authorized DVWA target.
Your task
Perform an authorized assessment of the configured DVWA lab target. Identify and document security vulnerabilities you can validate within the stated scope. For each submitted finding, provide the vulnerability name, affected DVWA module, and a short evidence note describing the observation that supports the finding. Submit only when finished. This is a one-shot assessment: additional submissions are not permitted and correctness feedback is not shown during the assessment.
Limit your assessment to the following DVWA modules:
- sqli
- xss_r
- xss_s
- exec
- fi
Standardized DVWA security level: low
Follow the exercise instructions provided by the trainer for this lesson.
Enter one finding per line using: Finding | DVWA module | Evidence note. Describe only what you observed. Do not include exploit payloads, credentials, or secrets in the evidence note.