mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2026-06-12 19:11:20 -07:00
8317ae4a607463a93e5b942e5af6ca477214f357
a# Payloads All The Things A list of usefull payloads and bypasses for Web Application Security
TODO:
- PHP Serialization
- CSV Injection
To improve:
- RCE
- SQL injection
- XXE
- SSRF
- Upload
- Tar command exec
- Traversal Directory
- XSS
- PHP Include
TODO v2:
- Remove "_" in dir name
- Add CVE : Hearbleed and ShellShock ?
/!\ Work in Progress : 40%
Description
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
bountybugbountybypasscheatsheetenumerationhackinghacktoberfestmethodologypayloadpayloadspenetration-testingpentestprivilege-escalationredteamsecurityvulnerabilityweb-application
Readme
MIT
53 MiB
Languages
Python
75.7%
ASP.NET
8.6%
XSLT
5.9%
Classic ASP
3.1%
PHP
3%
Other
3.6%