kh4sh3i / xmlrpc-exploit
Exploiting the xmlrpc.php on all WordPress versions
☆23Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for xmlrpc-exploit
- A simple automation tool to detect lfi, rce and ssti vulnerability☆55Updated 2 years ago
- A tool that automates the search for IDOR vulnerabilities in web apps and APIs☆50Updated 3 years ago
- Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE☆52Updated 2 weeks ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆68Updated 10 months ago
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated 7 months ago
- ☆64Updated last year
- ☆47Updated 2 years ago
- ☆18Updated last year
- Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.☆42Updated 8 months ago
- Run ffuf with the appropriate options to brute-force the directories using the awesome different wordlists.☆23Updated last year
- Subdomains enumeration, various scans and testing of some vulnerabilities.☆75Updated 5 months ago
- I collected it to help the bug hunter get a reward☆55Updated 2 years ago
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆34Updated last year
- Check if domain has bug bounty program or not☆29Updated last year
- An offensive security tool used to enumerate and spray passwords for O365 accounts on both Managed and Federated AD services.☆47Updated last year
- ☆21Updated 2 years ago
- Checks whether a domain is hosted on a cloud service such as AWS, Azure or CloudFlare☆57Updated last year
- Filter URLs to save your time.☆59Updated 2 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆48Updated 2 years ago
- Backup Files Wordlist Generator - generate a comprehensive list of potential backup file Wordlist based on a given list URL and backup fi…☆35Updated last week
- ☆43Updated last year
- ParamFirstCheck identifies in a list of urls those containing a parameter of the top 25 of the most vulnerable parameters for SQLi, LFI, …☆31Updated 11 months ago
- ☆68Updated 6 months ago
- The fastest way to setup XSSHunter. It has options for the official and Discord/Slack Forks☆40Updated 8 months ago
- This script reads a text file containing domains, fetches the subdomains from crt.sh☆10Updated last year
- A powerful bash script for massive XSS scanning leveraging Brute Logic's KNOXSS API☆58Updated last month
- Oneliner Bug Bounty Collection collected from GitHub to all bug bounty hunters☆27Updated 11 months ago
- BBSSRF - Bug Bounty SSRF is a powerful tool to check SSRF OOB connection☆38Updated last year
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated 8 months ago