Real reports from GGSec Cortex against deliberately-vulnerable test applications. Same layout you get on your own scan — executive summary, evidence-graded findings, reproducible proof-of-concept, risk matrix, remediation plan and compliance mapping.
Each report is the unmodified output of a real Cortex run — open the HTML to explore it interactively, or download the PDF.
The complete engine on a broad attack surface: SQL injection, reflected & stored XSS, JWT attacks, IDOR, NoSQL & LDAP injection, blind XXE and SSRF, PHP object injection, type-juggling auth bypass, path traversal and open redirect — plus known-CVE / dependency scanning and hard-coded-secret detection. 42 findings confirmed with hard evidence, showing the certainty-adjusted scoring end to end.
A single PHP application, examined in depth: reflected & stored XSS, SQL injection, LDAP injection, server-side template injection, path traversal, file-upload → RCE and prototype pollution — each finding backed by a reproducible proof-of-concept and mapped to MITRE ATT&CK.
A focused look at the kind of flaw pattern-only scanners miss: Server-Side Template Injection (second-order, store → render) and NoSQL injection. The AI follows the data flow; the dynamic engine proves execution — cleanly scored, low noise.
Vulnerabilities with zero visible response, proven anyway. The built-in collaborator captures the callback the target makes back to us: blind SSRF and a blind PHP object-injection → RCE gadget (deserialize → __destruct → outbound request) — each confirmed by an out-of-band HTTP callback, not guesswork.
The high-end module in action: a native raw-socket engine confirms a front-end/back-end desync by timing-differential — CL.TE and TE.CL proven (evidence strength High, 92/100), with a repeatability gate and 5/5 negative controls clean so it isn’t a fluke. This is the class pattern-only scanners can’t touch.
The class almost no scanner tests: prompt injection (OWASP LLM01 / CWE-1427). Cortex found — and proved — that a live DeepSeek-backed chatbot would obey attacker instructions (unauthenticated, CVSS 9.1). We hardened it in one file and re-scanned: clean. Vendor notified under responsible disclosure. An AI scanner that audits AI apps.
The modern-stack attack surface classic scanners never reach, in one pass. GraphQL (introspection leak, alias-amplification & depth-bomb DoS, resolver-level BFLA, SQLi via a string-interpolated argument), JWT RS256 → HS256 algorithm confusion forged from the published public key, mass assignment, broken function-level authorization, web cache deception, session fixation, unbounded-export DoS, NoSQL auth-bypass and both direct and indirect (RAG) prompt injection. 17 findings confirmed, zero false positives — and the report’s Exploitation Paths graph chains them into a full unauthenticated → admin takeover route.
The detection classes that need reasoning, not signatures. A business-logic invariant break (negative-quantity & over-100% discount price tampering, CWE-840); HTTP parameter pollution type-confusion (CWE-235); mass assignment proven by a read-back oracle — role escalated user → admin then restored (CWE-915); spoofable X-Forwarded-For trust granting internal access (CWE-807); a dedicated CSRF root-cause split from mass-assignment; and stored-XSS store → render. The Exploitation-Paths graph chains them into a session-fixation → IDOR → mass-assignment → admin takeover route. A companion SAST source-audit surfaces plaintext password storage (CWE-256) and hard-coded credentials (CWE-798), reported as Potential (verify) — findings a runtime-only scanner never sees.
These reports are from deliberately-vulnerable test applications. Point GGSec Cortex at your own environment and get the same client-ready output — evidence-graded findings, a prioritised fix plan and compliance mapping.
Reports were generated against intentionally-vulnerable test applications. For authorised security testing only. · GG Advanced IT Security — ggsec.de