RPI Labs: OWASP Mutillidae II
Version: 2.11.14 Security Level: 0 (Hosed) Hints: Enabled Not Logged In
Home | Login/Register | Toggle Hints | Toggle Security | Enforce TLS | Reset DB | View Log | View Captured Data
Content Security Policy (CSP)
Go Back   Back Help Me! Help Me!
Expand Hints Hints and Videos
Switch to Cross-Site Scripting (XSS) Switch to Cross-Origin Resource Sharing (CORS)
Abandon Hope All Ye Who Enter XSS Here
Message

Current Content Security Policy (CSP) Report To Endpoints Report-To: {"group": "csp-endpoint", "max_age": 10886400, "endpoints":[{"url": "includes/capture-data.php"}]}

Current Content Security Policy (CSP) Content-Security-Policy:
script-src 'self' 'nonce-44d76e70e192b9cad147f373ad082e089bc1840af36fa6dcec8655dd5896c72e' mutillidae.localhost;
style-src 'unsafe-inline' 'self' mutillidae.localhost;
img-src 'self' mutillidae.localhost www.paypalobjects.com;
connect-src 'self' mutillidae.localhost;
form-action 'self' mutillidae.localhost;
font-src 'none';
frame-src 'self' mutillidae.localhost;
media-src 'none';
object-src 'none';
default-src 'self';
frame-ancestors 'none';
report-uri includes/capture-data.php;
report-to csp-endpoint;











Browser: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
PHP Version: 8.1.27