Xalgorix · Offensive Security · Engine xalgo v1.4.2
Security Assessment Report
- Prepared for
- pentest ground
- Target
- https://pentest-ground.com:9000
- Engagement mode
- SINGLE
- Assessment window
- 19 Jun 2026 · 17 min
- Methodology
- 22-phase offensive workflow
- Reference
- 7c447778
Overall risk rating
CRITICAL
One or more vulnerabilities pose immediate risk of compromise.
100 / 100
Severity distribution
The engine reported 9 verified findings — 3 critical, 5 high, and 1 medium. Every finding was reproduced before inclusion.
critical
3
high
5
medium
1
low
0
info
0
Findings (9)
| ID | Severity | CVSS | Finding | |
|---|---|---|---|---|
| XALG-1 | critical | 9.8 | Remote Code Execution via Python Code Injection in /eval Endpoint | View → |
| XALG-2 | critical | 9.1 | OS Command Injection in /uptime/{flag} Endpoint | View → |
| XALG-3 | critical | 9.8 | SQL Injection with Full Database Dump — Plaintext Passwords Exposed | View → |
| XALG-4 | high | 7.5 | Plaintext Password Storage in Database | View → |
| XALG-5 | high | 7.5 | XML External Entity (XXE) Injection in /search Endpoint | View → |
| XALG-7 | high | 7.5 | Plaintext Password Exposure in User Endpoint Response | View → |
| XALG-8 | high | 7.5 | Token Expiration Not Enforced — Expired Tokens Remain Valid | View → |
| XALG-9 | high | 7.5 | Authentication Token Exposed in Public HTML Page | View → |
| XALG-6 | medium | 6.5 | Weak Token Generation Using MD5 Hash | View → |
Get this for your own target
Your first scan is just $1 — it runs the full 22-phase pipeline and produces a branded PDF like this. Credits never expire.
xalgorix