capture0x / SSTI-FINDERLinks
This tool is designed to detect and identify Server-Side Template Injection (SSTI) vulnerabilities in web applications
☆8Updated last year
Alternatives and similar repositories for SSTI-FINDER
Users that are interested in SSTI-FINDER are comparing it to the libraries listed below
Sorting:
- This repository contains random Nuclei templates I've created. Most of them based on recent security issues and exploits.☆15Updated last year
- A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticat…☆8Updated last year
- ParamFirstCheck identifies in a list of urls those containing a parameter of the top 25 of the most vulnerable parameters for SQLi, LFI, …☆35Updated last year
- A bash script that automates the process of service discovery on specified target hosts. The aim of the scripts is reducing scan time, in…☆13Updated 2 months ago
- ☆8Updated last year
- xdebug 2.5.5 RCE exploit☆31Updated 6 months ago
- Continuous Reconnaissance and Vulnerability Scanning for Bug Bounties☆18Updated last year
- Automate Blind SQL Injection with Python.☆23Updated 2 years ago
- A simple utility to perform reverse WHOIS lookups using whoisxml API☆44Updated 2 years ago
- ☆15Updated 2 years ago
- gh0str3con is a All in one cloud based web Recon tool.☆22Updated last year
- ☆19Updated last year
- Python tool to test known techniques to bypass 403 and 401 HTTP responses.☆37Updated 2 years ago
- "🔍 Subtron: Bash-driven subdomain seeker. Utilizes Subfinder, Amass, Assetfinder, and HTTPX to swiftly uncover live domains. Results sto…☆23Updated last month
- Find subdomains by searching public certificate records☆16Updated last year
- This tool allows you to find ssti vulnerability with ease!☆21Updated 2 years ago
- F5 BIG-IP Scanner scans for servers on shodan and checks to see if they are vulnerable.☆18Updated 2 years ago
- Template Nuclei SSTI☆31Updated last year
- Priv8 Tools Software Mass Dork Auto Exploit.☆13Updated 2 years ago
- Fetch & Filter Known URLs☆15Updated 3 years ago
- CVE-2025-4123 - Grafana Tool☆22Updated 2 months ago
- A small and fast bash script to automate LFI vulnerability.☆11Updated 2 years ago
- Automated HTTP Request Repeating With Burp Suite☆39Updated 2 years ago
- Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: …☆9Updated last year
- A BurpSuite extension for vulnerability Scanning☆27Updated last year
- Simple-XSS is a multiplatform cross-site scripting (XSS) vulnerability exploitation tool.☆48Updated last month
- Automate bug bounty recon using bash alias☆14Updated last year
- PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal☆17Updated last year
- Check if domain has bug bounty program or not☆28Updated 2 years ago
- my own 2fa bypass methodolgy☆24Updated last year