beescuit / crosssiteshellLinks
A websocket-based reverse (javascript) shell for XSS attacks.
☆30Updated 3 years ago
Alternatives and similar repositories for crosssiteshell
Users that are interested in crosssiteshell are comparing it to the libraries listed below
Sorting:
- A better way of querying certificate transparency logs☆87Updated 6 months ago
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticals…☆67Updated last year
- ☆28Updated 7 months ago
- 😛 Golang project to exploit an EL Injection vulnerability (CVE-2017-1000486) that affects the Primefaces 5.X versions. This project supp…☆19Updated 2 years ago
- Easily gather all routes related to a NextJs application through parsing of _buildManifest.js☆68Updated 2 years ago
- burp extension for brazilian stuff☆28Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆79Updated last year
- SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions…☆65Updated last year
- An MS Sharepoint and Frontpage Auditing Tool☆55Updated 10 months ago
- Session Hijacking Visual Exploitation☆207Updated last year
- ☆75Updated 3 months ago
- ☆90Updated 2 months ago
- ☆143Updated last year
- Tool to enable blind sql injection attacks against websockets using sqlmap☆66Updated 5 months ago
- Drupalwned is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆40Updated last year
- CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure☆91Updated last year
- Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the int…☆138Updated 10 months ago
- Joomla! < 4.2.8 - Unauthenticated information disclosure☆90Updated last year
- Colored Cat is a syntax highlighter file reader.☆15Updated last year
- Some tips for Bug Bounty using LibreOffice☆51Updated 7 months ago
- POC for CVE-2021-41091☆65Updated 2 years ago
- ☆172Updated 2 months ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆70Updated 2 years ago
- POC for CVE-2024-23897 Jenkins File-Read☆34Updated 7 months ago
- A couple of different scripts, made to automate attacks against NoSQL databases.☆66Updated last year
- PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22☆29Updated 2 years ago
- A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.☆105Updated 3 months ago
- Enumerate / Dump Docker Registry☆180Updated last year
- Adobe Experience Manager (AEM) hacking toolkit☆76Updated 2 weeks ago
- A simple python script to dump remote files through a local file read or local file inclusion web vulnerability.☆76Updated last year