An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions
☆122Jan 9, 2018Updated 8 years ago
Alternatives and similar repositories for jackson-rce-via-spel
Users that are interested in jackson-rce-via-spel are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Struts2の脆弱性S2-045, S2-055 および Jackson の脆弱性 CVE-2017-7525, CVE-2017-15095 の調査報告☆107Dec 13, 2017Updated 8 years ago
- RCE Exploit PoC for XMLDecoder☆63Aug 1, 2013Updated 12 years ago
- Spring messaging STOMP protocol RCE☆113Apr 12, 2018Updated 8 years ago
- Learn how to get a reverse shell from JIRA application server☆24Dec 2, 2018Updated 7 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploit☆105Dec 3, 2018Updated 7 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆83Jan 11, 2018Updated 8 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆55Mar 27, 2017Updated 9 years ago
- Collection of bypass gadgets to extend and wrap ysoserial payloads☆390Apr 16, 2022Updated 4 years ago
- A Java serializer in JavaScript☆81May 21, 2018Updated 8 years ago
- Java-Web-Security - Sichere Webanwendungen mit Java entwickeln☆221Updated this week
- Mogwai Java Management Extensions (JMX) Exploitation Toolkit☆175Jul 21, 2016Updated 10 years ago
- Java RMI enumeration and attack tool.☆748Sep 28, 2017Updated 8 years ago
- PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM☆52Mar 14, 2018Updated 8 years ago
- RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl☆210Mar 10, 2019Updated 7 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans☆583Sep 7, 2021Updated 4 years ago
- Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch☆115May 21, 2018Updated 8 years ago
- some java code i met or i used☆29May 7, 2019Updated 7 years ago
- JRE8u20_RCE_Gadget☆255Jul 1, 2016Updated 10 years ago
- Jenkins RCE PoC. From unauthenticated user to remote code execution, it's a hacker's dream!☆298Jun 10, 2019Updated 7 years ago
- spring mvc cve-2014-3625☆32Mar 11, 2016Updated 10 years ago
- ☆28Oct 16, 2017Updated 8 years ago
- PoC for CVE-2018-15133 (Laravel unserialize vulnerability)☆259Mar 10, 2024Updated 2 years ago
- fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java☆403Dec 16, 2022Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A collection of curated Java Deserialization Exploits☆594May 16, 2021Updated 5 years ago
- ssrf、ssrfIntranetFuzz、dnsRebinding、recordEncode、dnsPoisoning、Support ipv4/ipv6☆217Aug 17, 2017Updated 8 years ago
- IDS Bypass tricks☆122Jan 11, 2019Updated 7 years ago
- CVE-2018-6546-Exploit☆41Apr 15, 2018Updated 8 years ago
- ☆136Nov 6, 2015Updated 10 years ago
- Bypassing disabled exec functions in PHP (c) CRLF☆405Oct 2, 2020Updated 5 years ago
- A fake JDBC driver that allows OS command execution.☆126Oct 2, 2022Updated 3 years ago
- PoC code for crashing windows active directory☆35Sep 19, 2018Updated 7 years ago
- Multi-language web CGI interfaces exploits.☆395Aug 22, 2022Updated 3 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).☆522Mar 11, 2022Updated 4 years ago
- Java every minor versions.☆75Apr 19, 2023Updated 3 years ago
- CVE-2018-3245-PoC☆172Jul 13, 2021Updated 5 years ago
- SerialWriter is an incomplete implementation of Java serialization for study of Java deserialization vulnerabilities.☆105Feb 28, 2018Updated 8 years ago
- PoC for Scala and Groovy☆14Apr 4, 2016Updated 10 years ago
- Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12☆96Oct 18, 2022Updated 3 years ago
- Web Security Technology & Vulnerability Analysis Whitepapers☆549Jan 1, 2019Updated 7 years ago