xapax / xss-to-rce
Javascript payload that inject a malicious payload into the copy-buffer of the victim
☆35Updated 6 years ago
Alternatives and similar repositories for xss-to-rce
Users that are interested in xss-to-rce are comparing it to the libraries listed below
Sorting:
- ☆39Updated last year
- A simple automation tool to detect lfi, rce and ssti vulnerability☆55Updated 3 years ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆69Updated 4 years ago
- a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to …☆49Updated 3 years ago
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆30Updated last year
- Wordlist to bruteforce for LFI☆123Updated 5 years ago
- XSS reflector vulnerabilities exploitation extended.☆27Updated 3 years ago
- ☆48Updated 4 years ago
- HTTP verb tampering & methods enumeration☆58Updated 3 years ago
- Simple bash Script to automate initial recon using (httpx, puredns, regulator, wayback, katana, aquatone)☆34Updated last month
- golang tool to scan domains or single domains with know security issues against xmlrpc☆62Updated last year
- ☆55Updated 2 years ago
- Collection of content discovery wordlists in one wordlist.☆38Updated 3 years ago
- Web CTF CheatSheet 🐈☆34Updated 6 years ago
- ElasticSearch exploit and Pentesting guide for penetration tester☆27Updated 2 years ago
- 📚 An ultimate collection wordlists of the best-known CMS☆89Updated 11 months ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆79Updated 4 years ago
- ☆48Updated 4 years ago
- Intentionally Vulnerable Nodejs Application & APIs☆22Updated 3 years ago
- Pentest stuff☆49Updated last year
- ☆28Updated 10 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆71Updated 3 years ago
- ☆25Updated 2 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- Script for Bug Bounty☆28Updated 3 years ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆44Updated 11 months ago
- A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection☆70Updated 4 years ago
- Cheat sheet☆38Updated 5 years ago
- ☆56Updated last year