[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
☆228Apr 4, 2025Updated last year
Alternatives and similar repositories for CVE-2023-4357-Chrome-XXE
Users that are interested in CVE-2023-4357-Chrome-XXE are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆288Nov 20, 2023Updated 2 years ago
- JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021☆274Jun 6, 2025Updated 10 months ago
- Java内存马注入工具☆253Apr 8, 2023Updated 3 years ago
- 一款高性能 HTTP 内存代理 | 哥斯拉插件 | readteam | 红队 | 内存马 | Suo5 | Godzilla | 正向代理☆288Aug 8, 2023Updated 2 years ago
- Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入☆557Feb 1, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,365Nov 18, 2021Updated 4 years ago
- 一款支持自定义的 Java 回显载荷生成工具|A customizable Java echo payload generation tool.☆462Jan 12, 2025Updated last year
- ☆253Feb 25, 2024Updated 2 years ago
- 通过websocket在IIS8(Windows Server 2012)以上实现socks5代理☆112Jan 26, 2024Updated 2 years ago
- 多功能 java agent 内存马☆517Oct 8, 2023Updated 2 years ago
- 云安全利用工具-云平台AK/SK-WEB利用工具,添加AK/SK自动检测资源,无需手动执行,支持云服务器、存储桶、数据库操作☆588Dec 19, 2024Updated last year
- Registry API 未授权访问漏洞利用☆29May 17, 2023Updated 2 years ago
- 收集内存马打入方式☆508May 20, 2022Updated 3 years ago
- 寻找可利用的白文件☆560Aug 18, 2025Updated 7 months ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Java web路由内存分析工具☆439May 22, 2025Updated 10 months ago
- WebSocket 内存马/Webshell,一种新型内存马/WebShell技术☆1,493Apr 10, 2023Updated 3 years ago
- 亿赛通电子文档安全管理系统XStream反序列化漏洞任意文件上传利用☆120Aug 9, 2024Updated last year
- 一款让你不只在dubbo-sample、vulhub或者其他测试环境里检测和利用成功的Apache Dubbo 漏洞检测工具。☆171Aug 9, 2023Updated 2 years ago
- Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式☆548Mar 6, 2025Updated last year
- Nacos JRaft Hessian 反序列化 RCE 加载字节码 注入内存马 不出网利用☆848Jul 7, 2023Updated 2 years ago
- Yapi mock script RCE another version. Webshell way. 另一种 Webshell 方式的 Yapi 命令执行的方法 相比于其他的利用方式 更加微操和可控 影响更小☆66Jul 4, 2024Updated last year
- Some ReadObject Sink With JDBC☆245May 8, 2024Updated last year
- JavaPassDump☆275Jan 7, 2022Updated 4 years ago
- NordVPN Special Discount Offer • AdSave on top-rated NordVPN 1 or 2-year plans with secure browsing, privacy protection, and support for for all major platforms.
- 命令执行不回显但DNS协议出网的命令回显场景解决方案☆277Jan 10, 2023Updated 3 years ago
- JNDI在java高版本的利用工具,FUZZ利用链☆599Oct 8, 2022Updated 3 years ago
- 一个高度可定制化的JNDI和Java反序列化利用工具☆473Jan 17, 2023Updated 3 years ago
- 各种数据库的利用姿势☆1,034Jan 3, 2025Updated last year
- Extract website information from Vue☆286Aug 29, 2023Updated 2 years ago
- 一款适用于红蓝对抗中的仿真钓鱼系统☆1,538May 30, 2023Updated 2 years ago
- T Wiki 云安全知识文库,可能是国内首个云安全知识文库?☆1,039Dec 21, 2024Updated last year
- 互联网厂商API利用工具。☆569Sep 13, 2024Updated last year
- ExpFuzz字典☆21May 27, 2024Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆342Jun 7, 2022Updated 3 years ago
- 注入JVM进程 动态获取目标进程连接的数据库☆343Mar 6, 2022Updated 4 years ago
- 一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.☆2,177Aug 21, 2025Updated 7 months ago
- CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.☆320Sep 26, 2022Updated 3 years ago
- ebpf WebShell/内核马,一种新型内核马/WebShell技术☆353Jan 8, 2024Updated 2 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)☆293Aug 20, 2023Updated 2 years ago
- EXP for CVE-2023-28434 MinIO unauthorized to RCE☆320Apr 4, 2023Updated 3 years ago