A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
-
Updated
Jan 28, 2024 - Python
A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)
A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.
Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious threats. Let's delve into the tasks and functions that make Egyscan an indispensable tool in your security arsenal:
This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.
XXE vulnerability creator
Exploit Code, notes, and resources to accompany PortSwiggers' WebAcademy Labs.
Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.
WAFManis is a Protocol-Level WAF Evasion Fuzzing Tool that automates the discovery of evasion vulnerabilities in Web Application Firewalls (WAFs) by fuzzing HTTP requests to identify potential bypass techniques.
A collection of security tools for pentersion testing
Apache OFBiz 16.11.04 is susceptible to XML external entity injection (XXE injection)
A web crawler and vulnerability scanner tool developed by Rohit Ajariwal
Automates HTML injection, HTTP Parameter Pollution, and XXE attacks.
xxe smb/ftp server 适用于xxe的smb/ftp服务 docker一键启动 安全快捷
An automated tool for discovering vulnerabilities in GraphQL applications through fuzzing techniques, including OS Command Injection and XSS, with a focus on OWASP Top Ten vulnerabilities.
Pentester-Vurnability-Website
Add a description, image, and links to the xxe-injection topic page so that developers can more easily learn about it.
To associate your repository with the xxe-injection topic, visit your repo's landing page and select "manage topics."