ssti
There are 49 repositories under ssti topic.
nemesida-waf/waf-bypass
Check your WAF before an attacker does
vladko312/SSTImap
Automatic SSTI detection tool with interactive interface
Marven11/Fenjing
专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF
payloadbox/ssti-payloads
🎯 Server Side Template Injection Payloads
Adamkadaban/CTFs
CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done
DiogoMRSilva/websitesVulnerableToSSTI
Simple websites vulnerable to Server Side Template Injections(SSTI)
Yt1g3r/CVE-2019-3396_EXP
CVE-2019-3396 confluence SSTI RCE
ronin-rb/ronin-vulns
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.
Err0r-ICA/SCANter
Websites Vulnerability Scanner
darklotuskdb/SSTI-XSS-Finder
XSS Finder Via SSTI
MindPatch/hacking-lab
Small Vulnerable Web App
TrixSec/waymap
Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads.
cokeBeer/go-sec-code
Go-sec-code is a project for learning Go vulnerability code.
mpgn/CVE-2018-16341
CVE-2018-16341 - Nuxeo Remote Code Execution without authentication using Server Side Template Injection
filipkarc/ssti-flask-hacking-playground
App with Server Side Template Injection (SSTI) vulnerability - possible RCE - in Flask. Free vulnerable app for ethical hacking / penetration testing training.
DEMON1A/Blinder
A script written in python3 to spread blind cross-site scripting payloads on HTTP requests headers
muneebwanee/SubScanner
An automation tool that scans sub-domains, sub-domain takeover and then filters out xss, ssti, ssrf and more injection point parameters.
RiteshPuvvada/riteshpuvvada.github.io
Vulnerability Walkthrough
geniuszlyy/GenCrushSSTIExploit
is a PoC for CVE-2024-4040 tool for exploiting the SSTI vulnerability in CrushFTP
Acceis/exploit-CVE-2022-24780
iTop < 2.7.6 - (Authenticated) Remote command execution
anger/voyager-js
Voyager.js is a Node.js script designed for testing URLs for template injection vulnerabilities. It automates the process of appending known injection strings to URLs and monitors the responses for signs of successful injection.
LOIC-only-one/WebSecurityEmpire
Concernant le projet WebSecurityEmpire : Il s'agit de scripts pour tester la sécurité de site internet, cette collection peut être utilisé pour faire des présentations.
phanatagama/Web-CTF-Cheatsheet
Web CTF CheatSheet 🐈
leofvo/gossti
GoSSTI is a SSTI scanner for web application. Developed in Go.
Marven11/FenJing-Legacy
A payload generator for Jinja SSTI
RobinTrigon/ertssti
simple server site template injection scanner !
DanielAzulayy/FlaskyCTF-2020
The CTF requires an understanding of how Flask works in order to exploit an SSTI.
dotPY-hax/ssti-checker
rudimentary checker/scanner for server side template injection
dr34mhacks/Ginger-juice-shop
An Intentionally Vulnerable SSTI application for a beginner to an experienced.
storenth/lazyParam
A simple automation tool to detect LFI, RCE and SSTI vulnerability. Forked for PR and customization
TargetPackage/lazyParam
A simple automation tool to detect LFI, RCE and SSTI vulnerabilities.
testivy/wangding_2022_ctf_findit
2022 网鼎杯 玄武 web ctf thymeleaf SSTI bypass and memshell
TheWation/NodeJsSSTI
Express app with Pug templates demonstrating SSTI vulnerability and secure implementation for educational purposes.
TheWation/PythonSSTI
FastAPI app with Jinja2 SSTI vulnerability example to demonstrate security risks in web applications.
TrueBad0ur/ssti_java_concat_payload_generator
Simple ssti payload generator for java using concat technique
l0n3m4n/CVE-2022-29078
Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"