oppsec / pwnfaces
π Primefaces 5.X EL Injection Exploit (CVE-2017-1000486)
β19Updated last year
Related projects β
Alternatives and complementary repositories for pwnfaces
- π WSOB is a python tool created to exploit the new vulnerability on WSO2 assigned as CVE-2022-29464.β27Updated last year
- Wolfy AV Bypasserβ27Updated last year
- β43Updated last year
- https://github.com/ManhNho/AWAE-OSWEβ11Updated 4 years ago
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticalsβ¦β60Updated 10 months ago
- γπͺγLinux Backdoor based on ICMP protocolβ60Updated 8 months ago
- A websocket-based reverse (javascript) shell for XSS attacks.β29Updated 2 years ago
- β43Updated last year
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3β13Updated 2 years ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.β36Updated last year
- Yet Another PHP Shell - The most complete PHP reverse shellβ79Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.β68Updated 10 months ago
- User enumeration and password spraying tool for testing Azure ADβ68Updated 2 years ago
- A better way of querying certificate transparency logsβ75Updated last year
- PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)β87Updated 2 years ago
- Colored Cat is a syntax highlighter file reader.β16Updated 5 months ago
- Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.β44Updated 3 months ago
- β20Updated 7 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.β67Updated 2 years ago
- β7Updated last year
- γπ₯γCVE-2022-33891 - Apache Spark Command Injectionβ27Updated 2 years ago
- Robson is a simple LKM rootkit that uses the Linux kernel's kprobes tracing feature as a hooking mechanism.β12Updated last year
- An offensive security tool used to enumerate and spray passwords for O365 accounts on both Managed and Federated AD services.β47Updated 2 years ago
- β46Updated 2 years ago
- This script just implement a proxy over h2cSmuggler so you can navigate in your browser making requests to the back-end server.β37Updated 2 years ago
- Repository with quick triggers to help during Pentest in an Active Directory environment.β36Updated 3 weeks ago
- Crackmapexec custom scripts used in my internal pentests.β25Updated last year
- Just some random small tools for dealing with asp.net Forms Authentication Cookiesβ22Updated 3 years ago