YApi boolean-based injection exploit.
☆58Feb 8, 2023Updated 3 years ago
Alternatives and similar repositories for YApi-Exploit
Users that are interested in YApi-Exploit are comparing it to the libraries listed below
Sorting:
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆66Jul 4, 2024Updated last year
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆288Nov 20, 2023Updated 2 years ago
- 基于golang实现的impacket☆246Aug 28, 2023Updated 2 years ago
- CVE-2023-22515☆52Nov 10, 2023Updated 2 years ago
- Exchange 服务器安全性的辅助测试工具☆332Jul 21, 2023Updated 2 years ago
- 禅道相关poc☆172Jun 20, 2024Updated last year
- 一款让你不只在dubbo-sample、vulhub或者其他测试环境里检测和利用成功的Apache Dubbo 漏洞检测工具。☆172Aug 9, 2023Updated 2 years ago
- CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to des…☆103Apr 16, 2024Updated last year
- CVE-2022-37042 Zimbra Auth Bypass leads to RCE☆30Dec 9, 2022Updated 3 years ago
- 注入JVM进程 动态获取目标进程连接的数据库☆342Mar 6, 2022Updated 3 years ago
- ☆307Feb 27, 2025Updated last year
- Zimbra <9.0.0.p27 RCE☆106Nov 24, 2022Updated 3 years ago
- asp.net内存马检测工具☆283Aug 22, 2023Updated 2 years ago
- K8S安全攻防思维导图 | Docker安全攻防思维导图☆417Jun 22, 2022Updated 3 years ago
- 哥斯拉jsp/jspx免杀webshell生成器☆208Apr 28, 2023Updated 2 years ago
- dump lsass进程工具☆561Jul 20, 2023Updated 2 years ago
- 利用正则对不同的目标进行匹配,URL,js,遍历文件夹文件☆19Mar 2, 2022Updated 4 years ago
- C# 读取本机对外RDP连接记录和其他主机对该主机的连接记录,从而在内网渗透中获取更多可通内网网段信息以及定位运维管理人员主机☆431Jan 28, 2021Updated 5 years ago
- 一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.☆461Jan 12, 2025Updated last year
- ☆32Aug 15, 2022Updated 3 years ago
- 一款linux 内网渗透辅助工具☆78Jan 31, 2024Updated 2 years ago
- JavaPassDump☆272Jan 7, 2022Updated 4 years ago
- DBeaver数据库密码解密工具☆200Nov 29, 2023Updated 2 years ago
- 通过WindowsAPI获取用户凭证,并保存到文件中☆195Jun 18, 2024Updated last year
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,467Apr 25, 2024Updated last year
- 利用 Exchange 服务器 Web 接口爆破邮箱账户 | Brute force email accounts using Exchange server web endpoints☆93Sep 13, 2024Updated last year
- 配合 CVE-2023-22515 后台上传jar包实现RCE☆23Nov 9, 2023Updated 2 years ago
- Druid 密文解密工具☆137Dec 9, 2020Updated 5 years ago
- 检测查杀java内存马☆127Dec 5, 2023Updated 2 years ago
- POC for RCE using vulnerabilities described in VMSA-2023-0001☆148Jan 31, 2023Updated 3 years ago
- 建议使用新版:https://github.com/jar-analyzer/jar-analyzer☆896Nov 30, 2023Updated 2 years ago
- ☆17Jun 16, 2025Updated 8 months ago
- ☆95Feb 9, 2023Updated 3 years ago
- 帆软报表漏洞检测工具☆113Jun 10, 2025Updated 8 months ago
- C++枚举磁盘列表、遍历指定盘搜索特定类型文件/微信导出密钥,文件回传等功能☆153Jan 9, 2023Updated 3 years ago
- 利用oss实现http转发/cobalt strike上线☆371Nov 26, 2022Updated 3 years ago
- 一键获取nacos中的配置文件信息和绘制密码本☆121Jun 28, 2024Updated last year
- CVE-2020-1472 C++☆84Sep 2, 2022Updated 3 years ago
- RPC远程主机信息匿名扫描工具☆317Sep 30, 2022Updated 3 years ago