Metnew / uxss-db
πͺBrowser logic vulnerabilities
β689Updated 4 years ago
Alternatives and similar repositories for uxss-db:
Users that are interested in uxss-db are comparing it to the libraries listed below
- A tiny and cute URL fuzzerβ393Updated 2 years ago
- There is no pre-auth RCE in Jenkins since May 2017, but this is the one!β602Updated 5 years ago
- Content hijacking proof-of-concept using Flash, PDF and Silverlightβ381Updated 5 years ago
- Some of my exploits.β577Updated 4 years ago
- A collection of curated Java Deserialization Exploitsβ593Updated 3 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scansβ575Updated 3 years ago
- A tool for embedding XXE/XML exploits into different filetypesβ1,072Updated 3 months ago
- My Chrome and Safari exploit code + write-up repoβ528Updated 3 years ago
- Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).β500Updated 3 years ago
- HTTP file upload scanner for Burp Proxyβ490Updated last year
- Use HTTP Smuggling Lab to learn HTTP Smuggling.β347Updated 2 years ago
- SHELLING - a comprehensive OS command injection payload generatorβ443Updated 5 years ago
- All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilitiesβ780Updated 3 years ago
- Browser's XSS Filter Bypass Cheat Sheetβ1,125Updated 7 years ago
- Fuzzing Browsersβ310Updated 2 years ago
- Apache Solr Injection Researchβ571Updated 5 years ago
- ZAP/Burp plugin that generate script to reproduce a specific HTTP request (Intended for fuzzing or scripted attacks)β290Updated last year
- β419Updated 7 years ago
- From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extrasβ424Updated 5 years ago
- Vulnerability Labs for security analysisβ1,167Updated 4 years ago
- Vulncode-DB projectβ576Updated 3 years ago
- β687Updated 4 months ago
- Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labsβ836Updated this week
- Collection of bypass gadgets to extend and wrap ysoserial payloadsβ351Updated 2 years ago
- A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.β516Updated 4 years ago
- Java RMI enumeration and attack tool.β730Updated 7 years ago
- A mini webserver with FTP support for XXE payloadsβ328Updated last year
- Lab for exploring SSRF vulnerabilitiesβ246Updated 3 years ago
- Cure53 Browser Security White Paperβ292Updated 7 years ago
- Another way to bypass WAF Cheat Sheet (draft)β421Updated 6 years ago