capture0x / SSTI-FINDERLinks
This tool is designed to detect and identify Server-Side Template Injection (SSTI) vulnerabilities in web applications
☆8Updated last year
Alternatives and similar repositories for SSTI-FINDER
Users that are interested in SSTI-FINDER are comparing it to the libraries listed below
Sorting:
- This repository contains random Nuclei templates I've created. Most of them based on recent security issues and exploits.☆16Updated last year
- A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticat…☆8Updated last year
- ParamFirstCheck identifies in a list of urls those containing a parameter of the top 25 of the most vulnerable parameters for SQLi, LFI, …☆35Updated last year
- ☆14Updated 3 months ago
- hacking tools☆14Updated 2 years ago
- Find subdomains by searching public certificate records☆16Updated last year
- Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: …☆9Updated last year
- A BurpSuite extension for vulnerability Scanning☆27Updated last year
- Automated HTTP Request Repeating With Burp Suite☆38Updated 2 years ago
- xdebug 2.5.5 RCE exploit☆31Updated 6 months ago
- F5 BIG-IP Scanner scans for servers on shodan and checks to see if they are vulnerable.☆18Updated 2 years ago
- ☆8Updated last year
- https://www.nu11secur1ty.com☆23Updated last month
- Automatic Mass Tool for check and exploiting vulnerability in CVE-2023-3076 - MStore API < 3.9.9 - Unauthenticated Privilege Escalation (…☆17Updated last year
- ☆15Updated 2 years ago
- CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)☆29Updated last year
- A 1 Liner SQL Injection Attack using SQLMAP and various parameters that helps quickly check for a vulnerabilities during Bug Bounty☆41Updated 10 months ago
- A bash script that automates the process of service discovery on specified target hosts. The aim of the scripts is reducing scan time, in…☆13Updated 2 months ago
- A simple utility to perform reverse WHOIS lookups using whoisxml API☆44Updated last year
- ☆44Updated last year
- ☆21Updated 2 years ago
- My experiments in weaponizing ONOS applications (https://github.com/opennetworkinglab/onos)☆18Updated 8 months ago
- Apache OfBiz Auth Bypass Scanner for CVE-2023-51467☆11Updated last year
- auto exploit upload shell easily☆6Updated 3 years ago
- Check if domain has bug bounty program or not☆28Updated last year
- Repository of useful payloads and tips for pentesting/bug bounty.☆28Updated 8 months ago
- This tool allows you to find ssti vulnerability with ease!☆20Updated 2 years ago
- Python tool to test known techniques to bypass 403 and 401 HTTP responses.☆37Updated 2 years ago
- Several scripts are based on the Netlas.io search engine. They will allow you to carry out the reconnaissance phase before the pen test i…☆43Updated last month
- PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal☆17Updated last year