cnotin / RazorVulnerableAppLinks
DO NOT USE: this is a vulnerable ASP.NET web app using Razor templating engine. The vulnerability is a Server-Side Template Injection (SSTI). For training and testing purposes.
☆28Updated 5 years ago
Alternatives and similar repositories for RazorVulnerableApp
Users that are interested in RazorVulnerableApp are comparing it to the libraries listed below
Sorting:
- Gopher Tomcat Deployer☆48Updated 7 years ago
- tetctf2020_amf_writeups☆23Updated 4 years ago
- #BugBounty #BugBounty Tools #WebDeveloper Tool☆38Updated 7 months ago
- CVE-2021-40346 PoC (HAProxy HTTP Smuggling)☆41Updated 4 years ago
- In this repository I'll host my research and methodologies for auditing vulnerabilities☆29Updated 5 years ago
- Burp extension to generate multi-step CSRF POC.☆31Updated 6 years ago
- ☆56Updated 4 years ago
- Exploits developed by Mikael Kall☆48Updated 2 years ago
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆129Updated 2 years ago
- Authenticated SSRF in Grafana☆83Updated last year
- RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer☆56Updated 6 years ago
- Same Origin XSS challenge☆64Updated 3 years ago
- Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.☆48Updated 5 years ago
- Compiled dataset of Java deserialization CVEs☆60Updated 5 years ago
- Public Disclosures☆91Updated 3 years ago
- Practice hacking JWT tokens☆116Updated 3 years ago
- Looking for JAR files that are vulnerable to Log4j RCE (CVE‐2021‐44228)?☆45Updated 3 years ago
- Sample Spring Boot App Demonstrating RCE via Exposed env Actuator and H2 Database☆107Updated 5 years ago
- ☆36Updated 11 months ago
- A Burp Suite extension which augments your proxy traffic by injecting log4shell payloads into headers☆42Updated 4 years ago
- Burp Bounty profiles☆81Updated 3 years ago
- Generating payloads to reverse shell in different contexts of java.☆49Updated 3 years ago
- A tampered payload generator to Fuzz Web Application Firewalls☆35Updated 6 years ago
- This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a p…☆112Updated last year
- CSS injection vulnerability in Swagger UI☆35Updated 6 years ago
- Workshop given at Hack in Paris 2019☆125Updated 2 years ago
- ☆57Updated 3 years ago
- A extension for collecting parameters☆25Updated 5 years ago
- Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit☆92Updated last year
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆77Updated 5 years ago