RoqueNight / LFI---RCE-Cheat-Sheet
Transition form local file inclusion attacks to remote code exection
☆48Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for LFI---RCE-Cheat-Sheet
- Wordlist to bruteforce for LFI☆118Updated 5 years ago
- A tool that automates the search for IDOR vulnerabilities in web apps and APIs☆50Updated 3 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆77Updated 4 years ago
- A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection☆69Updated 3 years ago
- ☆39Updated 11 months ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆80Updated last year
- XSS Bypass☆28Updated 8 months ago
- LFI Payloads List coolected from github repos☆71Updated 4 years ago
- ☆108Updated last year
- ☆65Updated last year
- Describe how to use ffuf different options with examples☆80Updated last year
- Directory scans☆78Updated 8 months ago
- An MS Sharepoint and Frontpage Auditing Tool☆44Updated 3 years ago
- ☆35Updated last year
- Apache Tomcat exploit and Pentesting guide for penetration tester☆54Updated 2 years ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆59Updated last year
- ☆44Updated 5 months ago
- BurpSuite using the document and some extensions☆68Updated 4 years ago
- ☆64Updated last year
- Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...☆89Updated 3 years ago
- HTTP parameter discovery suite.☆59Updated 4 years ago
- A simple automation tool to detect lfi, rce and ssti vulnerability☆55Updated 2 years ago
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated 7 months ago
- Aspx reverse shell☆93Updated 4 years ago
- Tool to enable blind sql injection attacks against websockets using sqlmap☆56Updated last year
- HTTP verb tampering & methods enumeration☆51Updated 2 years ago
- OpenSSH 2.3 < 7.7 - Username Enumeration☆38Updated last year
- ☆146Updated last year
- Learn how to automate XSS, SSRF, LFI, SQLI, NoSQLi☆37Updated 3 years ago