This folder contains a compilation of the exploit and POCs from various online sources.
Apache Struts CVE-2018-11776 Exploit written in Python. Get RCE in one click.
HTML Exploit for Cross-Origin Resource Sharing where ALL origins are allowed.
HTML Exploit for Cross-Origin Resource Sharing where NULL origins are allowed.
XML file upload leading to Cross-Site Scripting. If the attack is successful, you will see a pop-up box containing: "Alert by Rohan's XML-to-XSS File!".
ShockWave Flash file upload leading to Cross-Site Scripting.
BitMap file upload leading to Cross-Site Scripting.
XML External Entity Injection attack leading to DOS Attack. Billion Laugh attack exploit.
EXIF Geolocation coordinates POC leading to Personal Information Leakage.
Lots of Pixels are loaded in memory leading to a DOS Attack. Pixel Flood attack exploit.
SVG File Upload leading to Cross-Site Scripting. If the attack is successful, you will see a pop-up box containing: "This is the alert box by Rohan's SVG file.".
SVG File Upload leading to XML External Entity Attack. This file is for Unix based system as it includes /etc/passwd file. If the attack is successful, you will see contents of /etc/passwd.
SVG File Upload leading to XML External Entity Attack. This file is for Windows-based systems as it includes /c:/boot.ini file. If the attack is successful, you will see the contents of /c:/boot.ini
GIF File Upload leading to Cross-Site Scripting.
Happy Hacking!:heart: