DataDog / vulnerable-java-application
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).
☆12Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for vulnerable-java-application
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- POC for CVE-2022-23648☆36Updated 2 years ago
- A curated list of argument injection vectors☆37Updated 3 months ago
- Dependency Confusion Security Testing Tool☆39Updated 2 years ago
- An Evil OIDC Server☆51Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 3 months ago
- Reference architecture and proof of concept implementation for supply chain security gateway☆23Updated last year
- ☆31Updated last year
- Tool to spray AWS Console IAM Logins☆25Updated 2 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆46Updated last year
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 3 years ago
- ☆31Updated last year
- Burp extension to generate multi-step CSRF POC.☆29Updated 5 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last year
- ☆16Updated 2 years ago
- PoC repository for CVE-2023-29007☆32Updated last year
- Utility for creating ZipSlip archives☆67Updated last year
- Create tar/zip archives that try to exploit zipslip vulnerability.☆45Updated 2 months ago
- ☆13Updated last year
- This script just implement a proxy over h2cSmuggler so you can navigate in your browser making requests to the back-end server.☆37Updated 2 years ago
- A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-sam…☆17Updated last year
- This repository offers insights and a proof-of-concept tool to exploit two significant deserialization vulnerabilities in Inductive Autom…☆45Updated 11 months ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆25Updated 9 months ago
- Burp Extension for AWS Signing☆86Updated last month
- ☆29Updated 7 months ago
- Enumerate AWS permissions and resources.☆64Updated 2 years ago
- DLL to open up calc.exe to demonstrate that you injected DLLs☆23Updated 3 years ago
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆38Updated 2 years ago