Web Security Penetration Test Report XPE-01
CyberJutsu Final Exam - XimiPlace Pentest Report
Final exam penetration testing report for CyberJutsu Academy, covering the XimiPlace authorized lab application. The assessment documents access control issues, stored XSS, exposed internal files, SSRF, second-order SQL injection, insecure Java deserialization, and an exploit chain leading to remote code execution.
- Published
- Jun 20, 2026
- Pages
- 82
- Environment
- CyberJutsu Lab - XimiPlace
- Report ID
- XPE-01
- Tags
- XimiPlace CyberJutsu Final Exam Web Pentest Security Lab Blackbox Testing OWASP
Assessment Overview
- Objective
- Document the CyberJutsu final exam black-box testing process, identified vulnerabilities, root causes, exploitation evidence, impact, and remediation guidance.
- Scope
- The assessment scope is limited to the XimiPlace lab application at ximiplace.exam.cyberjutsu-lab.tech.
- Authorization notice
- Testing was performed against the authorized XimiPlace lab environment for learning, security assessment practice, and application security reporting.
Key Topics
XimiPlace CyberJutsu Final Exam Web Pentest Security Lab Blackbox Testing OWASP Java Spring Data JPA React Docker Compose SQL
Tools Used
Burp Suite ffuf SecLists Webhook.site ngrok Python/Flask curl git Java JDK Browser Developer Tools
PDF Preview