xapax / xss-to-rceLinks
Javascript payload that inject a malicious payload into the copy-buffer of the victim
☆35Updated 7 years ago
Alternatives and similar repositories for xss-to-rce
Users that are interested in xss-to-rce are comparing it to the libraries listed below
Sorting:
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆30Updated last year
- HTTP verb tampering & methods enumeration☆62Updated 2 months ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- Cheat sheet☆36Updated 5 years ago
- ☆48Updated 4 years ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 5 years ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆70Updated 2 years ago
- A list of threat sinks used in the manual security source code review for application security☆73Updated 2 years ago
- Wordlist to bruteforce for LFI☆126Updated 6 years ago
- Web CTF CheatSheet 🐈☆34Updated 6 years ago
- XSS reflector vulnerabilities exploitation extended.☆27Updated 4 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆78Updated 5 years ago
- Collection Of Reverse Shell that can easily generate using Python3☆60Updated last year
- ☆56Updated 3 years ago
- ElasticSearch exploit and Pentesting guide for penetration tester☆29Updated 2 years ago
- ☆42Updated last year
- A simple automation tool to detect lfi, rce and ssti vulnerability☆56Updated 3 years ago
- Prototype Pollution Scanner☆126Updated 4 years ago
- ☆28Updated last year
- Chrome and Firefox extension that lists Amazon S3 Buckets while browsing☆125Updated 2 months ago
- Pentest stuff☆49Updated last year
- A python approach to interacting with web shells.☆30Updated 4 years ago
- Script for Bug Bounty☆29Updated 4 years ago
- A command-line tool for Cross-Site WebSocket Hijacking☆45Updated last year
- A "Spring4Shell" vulnerability scanner.☆49Updated 8 months ago
- ☆55Updated 4 years ago
- Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability☆86Updated last year
- ☆57Updated last year
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 3 years ago
- Scanner for Cross-Site WebSocket Hijacking☆42Updated 5 years ago