000pp / pwnfacesLinks
π Golang project to exploit an EL Injection vulnerability (CVE-2017-1000486) that affects the Primefaces 5.X versions. This project supports SOCKS proxy to prioritize anonymity.
β18Updated 2 years ago
Alternatives and similar repositories for pwnfaces
Users that are interested in pwnfaces are comparing it to the libraries listed below
Sorting:
- β45Updated 2 years ago
- Just some random small tools for dealing with asp.net Forms Authentication Cookiesβ24Updated 3 years ago
- https://github.com/ManhNho/AWAE-OSWEβ11Updated 4 years ago
- π WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.β26Updated 2 years ago
- PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)β87Updated 2 years ago
- Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.β53Updated 10 months ago
- User enumeration and password spraying tool for testing Azure ADβ70Updated 3 years ago
- Exploit and Check Script for CVE 2022-1388β58Updated 2 months ago
- An MS Sharepoint and Frontpage Auditing Toolβ50Updated 7 months ago
- This script implements the Proof of Concept attack from the Checkpoint research "NTLM Credentials Theft via PDF Files"β27Updated 7 years ago
- F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LABβ12Updated 2 years ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.β46Updated 2 years ago
- A "Spring4Shell" vulnerability scanner.β49Updated 5 months ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.β77Updated last year
- β26Updated 3 years ago
- CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGODβ68Updated 3 years ago
- LFI to RCE via phpinfo() assistance or via controlled log fileβ69Updated 2 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.β72Updated 3 years ago
- Determine the Version Running on the Palo Alto Network Firewall for the Global Protect Portalβ12Updated 4 years ago
- Drupalwned is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticalβ¦β40Updated last year
- Determine the running software version of a remote F5 BIG-IP management interface.β67Updated last year
- Pipe nmap verbose output to a usable format for httpx or host:port notation.β17Updated 3 years ago
- A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.β92Updated last year
- Open-Source Phishing Toolkitβ19Updated 4 years ago
- Wolfy AV Bypasserβ28Updated 2 years ago
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticalsβ¦β66Updated last year
- A Python based ingestor for BloodHoundβ84Updated 2 years ago
- β47Updated 3 years ago
- γπͺγLinux Backdoor based on ICMP protocolβ64Updated 7 months ago
- A better way of querying certificate transparency logsβ87Updated 3 months ago