synacktiv / astrolock
A purposely vulnerable application in order to demonstrate PHP payload smuggling techniques for PNG files.
☆37Updated 2 years ago
Alternatives and similar repositories for astrolock:
Users that are interested in astrolock are comparing it to the libraries listed below
- ElasticSearch exploit and Pentesting guide for penetration tester☆24Updated 2 years ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆60Updated 2 years ago
- A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it☆48Updated last year
- ☆16Updated last year
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆57Updated last year
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated 11 months ago
- Automated HTTP Request Repeating With Burp Suite☆35Updated last year
- CVE-2023-4634☆45Updated last year
- A Proof-Of-Concept for the CVE-2023-43770 vulnerability.☆33Updated last year
- Automatic Tools For Metabase Exploit Known As CVE-2023-38646☆27Updated last year
- CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection☆18Updated 10 months ago
- Exploits targeting vBulletin.☆76Updated last year
- WPXStrike is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's criticals…☆65Updated last year
- ☆25Updated 2 years ago
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 2 years ago
- A python3 script searching for secret on swaggerhub☆60Updated 2 years ago
- Drupalwned is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆39Updated last year
- Exploit for PrestaShop bockwishlist module 2.1.0 SQLi (CVE-2022-31101)☆25Updated 2 years ago
- Demo of various ways to exploit post based reflected XSS☆18Updated last year
- ☆25Updated 2 years ago
- Web cache poisoning vulnerability scanner.☆64Updated 2 years ago
- CVE-2023-6063 (WP Fastest Cache < 1.2.2 - UnAuth SQL Injection)☆29Updated last year
- Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)☆39Updated 2 years ago
- Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.☆44Updated 11 months ago
- ☆34Updated last year
- XSS Bypass☆28Updated last year
- CVE-2022-21907 Vulnerability PoC☆28Updated 3 years ago
- Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE☆52Updated 4 months ago
- ☆52Updated 2 years ago
- Make better use of the embedded browser that comes by default with Burp☆42Updated last year