The main goal of VWA is to provide a hands-on experience for security rookies on vulnerable web applications available for practicing and learning, so that they can attack realistic web environments… without going to jail :)
Vulnerable-Web-Application categorically includes Command Execution, File Inclusion, File Upload, Authentication Bypass, SQL and XSS. For database-requiring categories, it creates a database under localhost with one button during setup. In case of corrupted or changed databases, you can create a database again. (You have to find the database as i have made that hidden)