wh1t3p1g / ysoserial
forked from frohoff/ysoserial and added my own payloads.
☆151Updated 5 years ago
Alternatives and similar repositories for ysoserial:
Users that are interested in ysoserial are comparing it to the libraries listed below
- Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE☆176Updated 2 years ago
- attackRmi☆254Updated 4 years ago
- Weblogic IIOP CVE-2020-2551☆334Updated 5 years ago
- A simple python script to generate XML payloads works for XMLDecoder based on ProcessBuilder and Runtime exec☆149Updated 4 years ago
- Shiro RCE (Padding Oracle Attack)☆143Updated 5 years ago
- weblogic t3 deserialization rce☆271Updated 7 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆102Updated 5 years ago
- A vulnerable application exposing Spring Boot Actuators☆122Updated 6 years ago
- Spring Boot Actuator (jolokia) XXE/RCE☆317Updated 4 years ago
- RMI 反序列化环境 一步步☆210Updated 4 years ago
- Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行☆68Updated 5 years ago
- exploit Apache Flink Web Dashboard unauth rce on right way by python2 scripts☆90Updated 5 years ago
- Rusty Joomla RCE Exploit☆69Updated 2 years ago
- Apache Solr Exploits 🌟☆340Updated 4 years ago
- Apache Solr RCE via Velocity template☆108Updated 5 years ago
- fastjson bypass autotype 1.2.68 with Throwable and AutoCloseable.☆226Updated 2 years ago
- Weblogic coherence.jar RCE☆176Updated 4 years ago
- Burp extension intended to compact Burp extension tabs by hijacking them to own tab.☆130Updated 4 years ago
- ☆213Updated last year
- fastjson-1.2.47☆66Updated 5 years ago
- Weblogic CVE-2020-14645 UniversalExtractor JNDI injection getDatabaseMetaData()☆79Updated 4 years ago
- SpringBoot_Actuator_RCE☆96Updated 4 years ago
- MySQL JDBC Deserialization Payload / MySQL客户端jdbc反序列化漏洞payload☆13Updated 5 years ago
- 🐱💻 Poc of CVE-2019-7238 - Nexus Repository Manager 3 Remote Code Execution 🐱💻☆150Updated 6 years ago
- Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12☆94Updated 2 years ago
- ☆142Updated 4 years ago
- CVE-2020-36179~82 Jackson-databind SSRF&RCE☆80Updated 4 years ago
- CVE-2019-2725命令回显+webshell上传+最新绕过☆190Updated 5 years ago
- xxe oob receive file via web and ftp server☆97Updated 5 years ago
- Remote Command Execution Over Spark☆96Updated 7 years ago