Vulnerability: Content Security Policy (CSP) Bypass

You can include scripts from external sources, examine the Content Security Policy and enter a URL to include here:

As Pastebin and Hastebin have stopped working, here are some scripts that may, or may not help.

  • https://digi.ninja/dvwa/alert.js
  • https://digi.ninja/dvwa/alert.txt
  • https://digi.ninja/dvwa/cookie.js
  • https://digi.ninja/dvwa/forced_download.js
  • https://digi.ninja/dvwa/wrong_content_type.js

Pretend these are on a server like Pastebin and try to work out why some work and some do not work. Check the help for an explanation if you get stuck.

More Information

Module developed by Digininja.



Username: Unknown
Security Level: low
Locale: en
SQLi DB: mysql