Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
β600Jan 8, 2021Updated 5 years ago
Alternatives and similar repositories for Drupalgeddon2
Users that are interested in Drupalgeddon2 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- πProof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002β354Mar 29, 2019Updated 7 years ago
- Drupal enumeration & exploitation toolβ617Nov 4, 2020Updated 5 years ago
- CVE-2018-7600 Drupal RCEβ114Apr 18, 2018Updated 8 years ago
- Test CVE-2018-0296 and extract usernamesβ107Dec 9, 2018Updated 7 years ago
- Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.β205Feb 15, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- MS17-010β2,258Jun 20, 2023Updated 3 years ago
- Some scripts and exploitsβ147Jul 9, 2018Updated 8 years ago
- An implementation of NSA's ExplodingCan exploit in Pythonβ268Jan 4, 2018Updated 8 years ago
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scansβ582Sep 7, 2021Updated 4 years ago
- A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.β1,440Jan 19, 2024Updated 2 years ago
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Toolβ2,522Jan 21, 2020Updated 6 years ago
- Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)β498Dec 19, 2023Updated 2 years ago
- PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities.β2,019Oct 10, 2018Updated 7 years ago
- Linux privilege escalation exploit via snapd (CVE-2019-7304)β681May 9, 2019Updated 7 years ago
- Simple, predictable pricing with DigitalOcean hosting β’ AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Active Directory ACL exploitation with BloodHoundβ765Nov 18, 2021Updated 4 years ago
- Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Executionβ399Oct 11, 2017Updated 8 years ago
- Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!β297Jun 10, 2019Updated 7 years ago
- Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy. WPScan like plugin for Burp.β183Jul 30, 2019Updated 7 years ago
- Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.β1,933Sep 7, 2020Updated 5 years ago
- This script will generate payloads for basic intrusion detection avoidance. It utilizes publicly demonstrated techniques from several difβ¦β448Nov 30, 2023Updated 2 years ago
- Bypassing disabled exec functions in PHP (c) CRLFβ403Oct 2, 2020Updated 5 years ago
- A Java serializer in JavaScriptβ80May 21, 2018Updated 8 years ago
- ODAT: Oracle Database Attacking Toolβ1,773Mar 31, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A collection of curated Java Deserialization Exploitsβ593May 16, 2021Updated 5 years ago
- SA-CORE-2018-004 POC #drupalgeddon3β40Apr 28, 2018Updated 8 years ago
- Exploit for Drupal 7 <= 7.57 CVE-2018-7600β141Apr 26, 2018Updated 8 years ago
- Micro$oft Windows Hacking Packβ526Mar 6, 2018Updated 8 years ago
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts tβ¦β2,811Dec 18, 2021Updated 4 years ago
- A PowerShell example of the Windows zero day priv escβ327Sep 12, 2018Updated 7 years ago
- Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)β360Jan 11, 2020Updated 6 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploitβ104Dec 3, 2018Updated 7 years ago
- The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This toolβ¦β1,123Feb 10, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Privilege Escalation Project - Windows / Linux / Macβ2,618Oct 4, 2024Updated last year
- CVE-2018-13379β253Aug 14, 2019Updated 7 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressionsβ121Jan 9, 2018Updated 8 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on thβ¦β4,232May 11, 2023Updated 3 years ago
- β1,500Dec 31, 2022Updated 3 years ago
- Steal Net-NTLM Hash using Bad-PDFβ1,150Oct 20, 2025Updated 9 months ago
- An exploit for Apache Struts CVE-2018-11776β303Aug 26, 2018Updated 7 years ago