TheKingOfDuck / SBCVE
不定期记录一下浪费了时间去关注过的垃圾CVE漏洞。
☆119Updated last year
Alternatives and similar repositories for SBCVE
Users that are interested in SBCVE are comparing it to the libraries listed below
Sorting:
- JDBC Attack Tricks☆142Updated last year
- 将令你眼前一亮的XSS利用工具!☆110Updated 3 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案☆275Updated 2 years ago
- 2023白帽补天大会部分代码☆124Updated last year
- proof-of-concept for generating Java deserialization payload | Proxy MemShell☆191Updated 11 months ago
- 一个可以伪装上线Cobaltstrike的脚本☆132Updated 2 years ago
- Compatible with xray and nuclei poc framework☆195Updated 2 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)☆291Updated last year
- ☆107Updated 3 years ago
- Java Js Engine Payloads All in one☆271Updated last year
- fastjson不出网利用、c3p0☆252Updated 3 years ago
- ☆138Updated 2 years ago
- Apache Dubbo (CVE-2023-23638)漏洞利用的工程化实践☆223Updated last year
- 适用于weblogic和Tomcat的无文件的内存马(memshell)☆266Updated 3 years ago
- 使用WindowsAPI写的一些渗透小工具☆99Updated 3 years ago
- 懒鬼插件/审计过的后的渗透插件/我凭本事打的SESSION凭什么还要我自己动手后渗透?☆193Updated 3 months ago
- fastjson 80 远程代码执行漏洞复现☆193Updated 2 years ago
- A list for Spring Security☆123Updated last year
- A Go library for generating Java deserialization payloads.☆155Updated 8 months ago
- 适用于burpsuite渗透工具的多类型恶意文件代码、漏洞测试payload、脚本代码快速获取复制的在线辅助插件。☆65Updated 3 years ago
- CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!☆93Updated 6 months ago
- Some ReadObject Sink With JDBC☆215Updated last year
- 一款针对于IDE的反制蜜罐 IDE-honeypot☆107Updated 2 years ago
- Apache RocketMQ 远程代码执行漏洞(CVE-2023-33246) Exploit☆107Updated last year
- Java应用的一些配置文件字典,来源于公开的字典与平时收集☆306Updated last year
- 自己积累的一些Java反序列化利用链☆88Updated 2 years ago
- 禅道相关poc☆164Updated 10 months ago
- ☆283Updated 3 years ago
- 禅道研发项目管理系统`misc-captcha-user`认证绕过后台命令注入漏洞☆98Updated 2 years ago
- Java表达式语句生成器☆188Updated last year