A Burp Extender for checking for struts 2 RCE vulnerabilities.
☆286Jun 4, 2024Updated last year
Alternatives and similar repositories for Struts2-RCE
Users that are interested in Struts2-RCE are comparing it to the libraries listed below
Sorting:
- 一个简单的Fastjson反序列化检测burp插件☆970Jun 18, 2021Updated 4 years ago
- 一款基于BurpSuite的被动式shiro检测插件☆1,795Dec 14, 2022Updated 3 years ago
- 一款基于BurpSuite的被动式FastJson检测插件☆1,238Oct 1, 2022Updated 3 years ago
- SpringScan 漏洞检测 Burp插件☆605Nov 14, 2023Updated 2 years ago
- CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks☆840Jun 13, 2023Updated 2 years ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆124May 14, 2021Updated 4 years ago
- Shiro RememberMe 1.2.4 反序列化漏洞图形化检测工具(Shiro-550)☆877Dec 16, 2022Updated 3 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,012May 21, 2024Updated last year
- 通达OA综合利用工具☆516Mar 17, 2021Updated 4 years ago
- Shiro反序列化利用工具,支持新版本(AES-GCM)Shiro的key爆破,配合ysoserial,生成回显Payload☆897May 28, 2021Updated 4 years ago
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆770Jan 26, 2022Updated 4 years ago
- xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。☆1,229May 18, 2023Updated 2 years ago
- Burp被动扫描流量转发插件☆1,459Jun 17, 2024Updated last year
- Spring Boot Actuator未授权访问【XXE、RCE】单/多目标检测☆521May 21, 2020Updated 5 years ago
- Struts2漏洞扫描利用工具 - Golang版. Struts2 Scanner Written in Golang☆572Jan 10, 2022Updated 4 years ago
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,467Apr 25, 2024Updated last year
- Shiro<=1.2.4反序列化,一键检测工具☆988Mar 4, 2021Updated 4 years ago
- 致远OA综合利用工具☆418Jun 3, 2021Updated 4 years ago
- 新版将不再对外公开发布。天蝎权限管理工具采用Java平台的JavaFX技术开发的桌面客户端,支持跨平台运行,目前基于JDK1.8开发,运行必须安装JDK或JRE 1.8,注意不能是open jdk,只能是oracle的jdk。 天蝎权限管理工具基于冰蝎加密流量进行WebSh…☆387Mar 22, 2021Updated 4 years ago
- Struts2系列漏洞检查工具☆434Sep 27, 2019Updated 6 years ago
- 用于帮助企业内部快速扫描log4j2的jndi漏洞的burp插件☆213Apr 18, 2023Updated 2 years ago
- Fiora:漏洞PoC框架Nuclei的图形版。快捷搜索PoC、一键运行Nuclei。即可作为独立程序运行,也可作为burp插件使用。☆1,273Jul 2, 2025Updated 7 months ago
- Shiro550/Shiro721 一键化利用工具,支持多种回显方式☆1,950Jun 4, 2021Updated 4 years ago
- 一款基于webshell命令执行功能实现的GUI webshell管理工具,支持流量加密☆218Jun 4, 2021Updated 4 years ago
- shiro 反序列 命令执行辅助检测工具☆1,561May 21, 2024Updated last year
- heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等☆1,433May 21, 2024Updated last year
- MDUT - Multiple Database Utilization Tools☆2,190Sep 22, 2023Updated 2 years ago
- Shiro反序列化回显利用、内存shell、检查 Burp插件☆217Sep 1, 2022Updated 3 years ago
- A Swagger API Exploit☆1,370Jun 7, 2024Updated last year
- OAExploit一款基于产品的一键扫描工具。☆1,482Sep 20, 2022Updated 3 years ago
- Burp suite 分块传输辅助插件☆2,022Feb 23, 2022Updated 4 years ago
- Log4j2 RCE Passive Scanner plugin for BurpSuite☆830Aug 4, 2023Updated 2 years ago
- Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件☆1,314Jun 29, 2024Updated last year
- Weblogic一键漏洞检测工具,V1.5,更新时间:20200730☆2,265May 22, 2023Updated 2 years ago
- ☆168May 30, 2022Updated 3 years ago
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,116Jan 23, 2026Updated last month
- 高危漏洞精准检测与深度利用框架☆1,456Jan 8, 2023Updated 3 years ago
- Shiro-550 不依赖CC链利用工具☆451Jun 19, 2024Updated last year
- Fastjson <= 1.2.47 远程命令执行漏洞利用工具及方法☆400Jan 24, 2025Updated last year