I would like to submit the attached patch to avoid hard-coding "/WebGoat" as the webapp's context path, at least for the HTTP splitting lesson. This issue has also been reported in July 2007; see https://lists.owasp.org/pipermail/owasp-webgoat/2007-July/000432.html Also see Issue 15 http://code.google.com/p/webgoat/issues/detail?id=15 git-svn-id: http://webgoat.googlecode.com/svn/trunk@366 4033779f-a91e-0410-96ef-6bf7bf53c507
Description
WebGoat is a deliberately insecure application
Languages
JavaScript
51.3%
Java
32.8%
HTML
11.9%
CSS
3.9%