Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
β593Jan 8, 2021Updated 5 years ago
Alternatives and similar repositories for Drupalgeddon2
Users that are interested in Drupalgeddon2 are comparing it to the libraries listed below
Sorting:
- πProof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002β353Mar 29, 2019Updated 6 years ago
- Drupal enumeration & exploitation toolβ612Nov 4, 2020Updated 5 years ago
- Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.β206Feb 15, 2024Updated 2 years ago
- Test CVE-2018-0296 and extract usernamesβ106Dec 9, 2018Updated 7 years ago
- CVE-2018-7600 Drupal RCEβ114Apr 18, 2018Updated 7 years ago
- MS17-010β2,231Jun 20, 2023Updated 2 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scansβ584Sep 7, 2021Updated 4 years ago
- Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)β498Dec 19, 2023Updated 2 years ago
- Some scripts and exploitsβ148Jul 9, 2018Updated 7 years ago
- A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.β1,405Jan 19, 2024Updated 2 years ago
- A collection of curated Java Deserialization Exploitsβ591May 16, 2021Updated 4 years ago
- Linux privilege escalation exploit via snapd (CVE-2019-7304)β682May 9, 2019Updated 6 years ago
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.β1,992Oct 10, 2018Updated 7 years ago
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Toolβ2,514Jan 21, 2020Updated 6 years ago
- Active Directory ACL exploitation with BloodHoundβ755Nov 18, 2021Updated 4 years ago
- Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Executionβ395Oct 11, 2017Updated 8 years ago
- CVE-2018-13379β254Aug 14, 2019Updated 6 years ago
- A PowerShell example of the Windows zero day priv escβ328Sep 12, 2018Updated 7 years ago
- ODAT: Oracle Database Attacking Toolβ1,743Jul 27, 2024Updated last year
- Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.β1,917Sep 7, 2020Updated 5 years ago
- Bypassing disabled exec functions in PHP (c) CRLFβ406Oct 2, 2020Updated 5 years ago
- A Java serializer in JavaScriptβ80May 21, 2018Updated 7 years ago
- This script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several difβ¦β445Nov 30, 2023Updated 2 years ago
- Micro$oft Windows Hacking Packβ525Mar 6, 2018Updated 7 years ago
- The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This toolβ¦β1,128Feb 10, 2021Updated 5 years ago
- Exploit for Drupal 7 <= 7.57 CVE-2018-7600β139Apr 26, 2018Updated 7 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts tβ¦β2,732Dec 18, 2021Updated 4 years ago
- Privilege Escalation Project - Windows / Linux / Macβ2,602Oct 4, 2024Updated last year
- Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective waβ¦β729Nov 19, 2017Updated 8 years ago
- Perform a MitM attack and extract clear text credentials from RDP connectionsβ1,449Nov 20, 2025Updated 3 months ago
- Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)β364Jan 11, 2020Updated 6 years ago
- SA-CORE-2018-004 POC #drupalgeddon3β41Apr 28, 2018Updated 7 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploitβ106Dec 3, 2018Updated 7 years ago
- A Ruby framework designed to aid in the penetration testing of WordPress systems.β1,043Nov 24, 2019Updated 6 years ago
- β1,489Dec 31, 2022Updated 3 years ago
- Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!β298Jun 10, 2019Updated 6 years ago
- Exploit written in Python for CVE-2018-15473 with threading and export formatsβ533Jul 12, 2024Updated last year
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on thβ¦β4,173May 11, 2023Updated 2 years ago
- SSRF (Server Side Request Forgery) testing resourcesβ2,483Oct 12, 2024Updated last year