Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
β600Jan 8, 2021Updated 5 years ago
Alternatives and similar repositories for Drupalgeddon2
Users that are interested in Drupalgeddon2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- πProof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002β354Mar 29, 2019Updated 7 years ago
- Drupal enumeration & exploitation toolβ618Nov 4, 2020Updated 5 years ago
- CVE-2018-7600 Drupal RCEβ114Apr 18, 2018Updated 8 years ago
- Test CVE-2018-0296 and extract usernamesβ107Dec 9, 2018Updated 7 years ago
- Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.β206Feb 15, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- MS17-010β2,255Jun 20, 2023Updated 3 years ago
- Some scripts and exploitsβ147Jul 9, 2018Updated 8 years ago
- An implementation of NSA's ExplodingCan exploit in Pythonβ270Jan 4, 2018Updated 8 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scansβ583Sep 7, 2021Updated 4 years ago
- A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.β1,439Jan 19, 2024Updated 2 years ago
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Toolβ2,521Jan 21, 2020Updated 6 years ago
- Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)β498Dec 19, 2023Updated 2 years ago
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.β2,019Oct 10, 2018Updated 7 years ago
- Linux privilege escalation exploit via snapd (CVE-2019-7304)β683May 9, 2019Updated 7 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Active Directory ACL exploitation with BloodHoundβ764Nov 18, 2021Updated 4 years ago
- Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Executionβ399Oct 11, 2017Updated 8 years ago
- Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!β298Jun 10, 2019Updated 7 years ago
- Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy. WPScan like plugin for Burp.β184Jul 30, 2019Updated 6 years ago
- Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.β1,930Sep 7, 2020Updated 5 years ago
- This script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several difβ¦β448Nov 30, 2023Updated 2 years ago
- Bypassing disabled exec functions in PHP (c) CRLFβ405Oct 2, 2020Updated 5 years ago
- A Java serializer in JavaScriptβ81May 21, 2018Updated 8 years ago
- ODAT: Oracle Database Attacking Toolβ1,772Mar 31, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A collection of curated Java Deserialization Exploitsβ594May 16, 2021Updated 5 years ago
- SA-CORE-2018-004 POC #drupalgeddon3β41Apr 28, 2018Updated 8 years ago
- Exploit for Drupal 7 <= 7.57 CVE-2018-7600β141Apr 26, 2018Updated 8 years ago
- Micro$oft Windows Hacking Packβ526Mar 6, 2018Updated 8 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts tβ¦β2,800Dec 18, 2021Updated 4 years ago
- A PowerShell example of the Windows zero day priv escβ328Sep 12, 2018Updated 7 years ago
- Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)β362Jan 11, 2020Updated 6 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploitβ105Dec 3, 2018Updated 7 years ago
- The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This toolβ¦β1,125Feb 10, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Privilege Escalation Project - Windows / Linux / Macβ2,611Oct 4, 2024Updated last year
- CVE-2018-13379β253Aug 14, 2019Updated 6 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressionsβ122Jan 9, 2018Updated 8 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on thβ¦β4,227May 11, 2023Updated 3 years ago
- β1,499Dec 31, 2022Updated 3 years ago
- Steal Net-NTLM Hash using Bad-PDFβ1,150Oct 20, 2025Updated 9 months ago
- An exploit for Apache Struts CVE-2018-11776β303Aug 26, 2018Updated 7 years ago