000pp / pwnfacesLinks
π Golang project to exploit an EL Injection vulnerability (CVE-2017-1000486) that affects the Primefaces 5.X versions. This project supports SOCKS proxy to prioritize anonymity.
β18Updated 2 years ago
Alternatives and similar repositories for pwnfaces
Users that are interested in pwnfaces are comparing it to the libraries listed below
Sorting:
- A websocket-based reverse (javascript) shell for XSS attacks.β30Updated 3 years ago
- An MS Sharepoint and Frontpage Auditing Toolβ57Updated last year
- β45Updated 2 years ago
- Just some random small tools for dealing with asp.net Forms Authentication Cookiesβ28Updated 4 years ago
- Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerabilityβ87Updated last year
- β34Updated 3 years ago
- A better way of querying certificate transparency logsβ87Updated 7 months ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.β81Updated last year
- β27Updated 3 years ago
- PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)β87Updated 3 years ago
- BurpSuite extension to convert requests into bcheck scriptsβ33Updated 2 years ago
- π WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.β26Updated 2 years ago
- A Python based ingestor for BloodHoundβ85Updated 3 years ago
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticalsβ¦β68Updated last year
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.β36Updated 3 years ago
- Tool to enable blind sql injection attacks against websockets using sqlmapβ66Updated 6 months ago
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)β77Updated last year
- β42Updated last year
- LFI to RCE via phpinfo() assistance or via controlled log fileβ72Updated 2 years ago
- OpenNetAdmin 18.1.1 - Remote Code Executionβ31Updated 5 years ago
- F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LABβ12Updated 2 years ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.β48Updated 2 years ago
- β145Updated last year
- β41Updated 2 years ago
- Scan for and exploit the zerologon vulnerability.β10Updated 5 years ago
- Notes Template/Checklist for PEN-300 OSEPβ16Updated 4 years ago
- Adobe Experience Manager (AEM) hacking toolkitβ91Updated last month
- Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HEβ54Updated last year
- Drupalwned is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticalβ¦β40Updated last year
- β27Updated 3 years ago