tranquac / cmd-inject-header
Simple tool to check command injection in headers of http request
☆19Updated 2 years ago
Alternatives and similar repositories for cmd-inject-header:
Users that are interested in cmd-inject-header are comparing it to the libraries listed below
- PoC for XSS in org.webjars:swagger-ui [3.14.2, 3.36.2]☆53Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆75Updated last year
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆58Updated last year
- Nuclei Templates to reproduce Cracking the lens's Research☆125Updated 3 years ago
- Spring4Shell Burp Scanner☆71Updated 2 years ago
- ☆33Updated 2 years ago
- ☆25Updated 4 years ago
- An MS Sharepoint and Frontpage Auditing Tool☆48Updated 4 months ago
- This repository contains proof of concept for zero days and CVEs that were found by Omar Hashem through Security Research☆44Updated 2 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- ☆60Updated 3 years ago
- Modified Nuclei Templates Version to FUZZ Host Header☆49Updated 3 years ago
- Authorization-Nuclei-Templates☆38Updated 6 months ago
- nuclei framework scripts☆34Updated 2 years ago
- Web cache poisoning vulnerability scanner.☆65Updated 2 years ago
- BChecks collection for Burp Suite Professional☆96Updated 9 months ago
- ☆36Updated 2 years ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- nuclei-bb-templates☆49Updated 2 years ago
- 🚀 Sling Shot R3con: Automate Your Bug Bounty and Pentest Reconnaissance with Project Discovery tools 🎯☆24Updated last year
- A GO module to get domain name from SSL certificates when an IP address is provided.☆33Updated last year
- Perform with Massive Command Injection (Chamilo)☆21Updated last year
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 2 years ago
- Simple Django to show post-exploitation options when server-side template injection (SSTI) is present in app using Django Templates.☆16Updated 3 years ago
- Process URLs and remove duplicate query parameters.☆28Updated last year
- ☆33Updated 2 years ago
- An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.☆43Updated 4 years ago
- ☆95Updated 3 years ago
- Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.☆44Updated last year
- All Nuclei Templates☆69Updated 2 weeks ago