lunasec-io / spring-rce-vulnerable-app
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228) and the possible Spring RCE vulnerability.
☆34Updated 3 years ago
Alternatives and similar repositories for spring-rce-vulnerable-app
Users that are interested in spring-rce-vulnerable-app are comparing it to the libraries listed below
Sorting:
- Looking for JAR files that are vulnerable to Log4j RCE (CVE‐2021‐44228)?☆45Updated 3 years ago
- try to determine if a host is vulnerable to SpringShell CVE‐2022‐22965 and CVE‐2022‐22963☆23Updated 3 years ago
- Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.☆47Updated 4 years ago
- Nmap script to check vulnerability CVE-2021-21975☆28Updated 4 years ago
- Utility for creating ZipSlip archives☆72Updated 2 years ago
- Intentionally Vulnerable to Spring4Shell☆52Updated 3 years ago
- Everything I needed to understand what was going on with "Spring4Shell" - translated source materials, exploit, links to demo apps, and m…☆108Updated 3 years ago
- Dockerized POC for CVE-2022-42889 Text4Shell☆75Updated 2 years ago
- RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets fro…☆107Updated 4 years ago
- Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)☆88Updated 2 years ago
- CVE-2021-40346 PoC (HAProxy HTTP Smuggling)☆40Updated 3 years ago
- ☆30Updated last year
- A fingerprint generation helper for nuclei network templates☆72Updated 2 years ago
- NSE script to detect ProxyOracle☆14Updated 3 years ago
- Argument Injection in Dragonfly Ruby Gem☆16Updated 3 years ago
- Burp extension to generate multi-step CSRF POC.☆30Updated 5 years ago
- ☆56Updated 3 years ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- Burp Extension that lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap☆36Updated 3 years ago
- ☆26Updated 11 months ago
- client-side prototype pullution vulnerability scanner☆46Updated 3 years ago
- This little script for gathering chaos.projectdiscovery.io recon data in an organized way and finding the daily differences on it☆17Updated 4 years ago
- ☆86Updated 3 years ago
- DO NOT RUN THIS.☆47Updated 3 years ago
- an Evil Java RMI Registry.☆50Updated 2 years ago
- A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.☆5Updated 2 years ago
- A Burp extension to show the Collaborator client in a tab☆23Updated 2 years ago
- spring4shell | CVE-2022-22965☆21Updated 2 years ago
- Apache commons text - CVE-2022-42889 Text4Shell proof of concept exploit.☆55Updated last year
- tetctf2020_amf_writeups☆23Updated 4 years ago