filipkarc / ssti-flask-hacking-playgroundLinks
App with Server Side Template Injection (SSTI) vulnerability - possible RCE - in Flask. Free vulnerable app for ethical hacking / penetration testing training.
☆15Updated 2 years ago
Alternatives and similar repositories for ssti-flask-hacking-playground
Users that are interested in ssti-flask-hacking-playground are comparing it to the libraries listed below
Sorting:
- Send controlled amount of bytes, send msf-pattern, calculate offset, custom buffer, badcharacters all in one.☆16Updated last year
- ☆34Updated 3 years ago
- CVE-2021-40346 PoC (HAProxy HTTP Smuggling)☆41Updated 3 years ago
- A webshell application and interactive shell for pentesting Apache Tomcat servers.☆114Updated 5 months ago
- Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE☆16Updated 2 years ago
- CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC☆118Updated last year
- A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.☆114Updated 5 months ago
- Dockerized POC for CVE-2022-42889 Text4Shell☆76Updated 2 years ago
- Apache Spark Shell Command Injection Vulnerability☆88Updated 2 years ago
- POC for CVE-2022-47966 affecting multiple ManageEngine products☆127Updated 2 years ago
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆55Updated last year
- Exploits targeting vBulletin.☆76Updated 2 years ago
- cve-2022-42889 Text4Shell CVE-2022-42889 affects Apache Commons Text versions 1.5 through 1.9. It has been patched as of Commons Text ver…☆39Updated 2 years ago
- PoC for CVE-2022-23940☆12Updated 2 months ago
- CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.☆76Updated last year
- ☆37Updated 2 years ago
- POC for CVE-2023-38646☆20Updated last year
- GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab…☆141Updated 2 years ago
- CVE Collection of jQuery UI XSS Payloads☆119Updated 2 years ago
- ☆103Updated 2 years ago
- PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)☆87Updated 2 years ago
- Automatic Tools For Metabase Exploit Known As CVE-2023-38646☆27Updated last year
- Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)☆118Updated last year
- SCodeScanner stands for Source Code scanner where the user can scans the source code for finding the Critical Vulnerabilities.☆161Updated 2 years ago
- ☆112Updated last year
- CVE-2022-1388 F5 BIG-IP iControl REST RCE☆37Updated 3 years ago
- CVE-2021-41773 | CVE-2021-42013 Exploit Tool (Apache/2.4.49-2.4.50)☆9Updated 3 years ago
- [PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)☆90Updated 2 years ago
- Burp Suite's extension to scan and crawl Single Page Applications☆105Updated 2 years ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.☆46Updated 2 years ago