Check your WAF before an attacker does
-
Updated
Mar 24, 2023 - Python
Check your WAF before an attacker does
Automatic SSTI detection tool with interactive interface
CTF Cheat Sheet + Writeups / Files for some of the Cyber CTFs that I've done
XSS Finder Via SSTI
Small Vulnerable Web App
Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.
App with Server Side Template Injection (SSTI) vulnerability - possible RCE - in Flask. Free vulnerable app for ethical hacking / penetration testing training.
An automation tool that scans sub-domains, sub-domain takeover and then filters out xss, ssti, ssrf and more injection point parameters.
Vulnerability Walkthrough
A script written in python3 to spread blind cross-site scripting payloads on HTTP requests headers
iTop < 2.7.6 - (Authenticated) Remote command execution
Web CTF CheatSheet
OWASP Foundation Web Respository
PHP Source Code Analysis
Add a description, image, and links to the ssti topic page so that developers can more easily learn about it.
To associate your repository with the ssti topic, visit your repo's landing page and select "manage topics."