๐ Vulnerability Exploitation
This category collects exploit engines designed to automate SQL injection dumps, XSS injection testing, Command Injection shells, LFI/RFI parsing, and SSTI/SSRF mapping.
Tool Catalog
Select a tool below to view detailed specifications, cheatsheets, or definitions.
SQLmap
Automated SQL injection discovery, DBMS database extractor, and shell execution suite.
XSStrike
Context-aware Cross-Site Scripting fuzzer utilizing script reflection analyzers.
Commix
Automated Command Injection Exploiter capable of generating shell environments.
Ghauri / BBQSQL
Advanced alternative blind SQL injection detection and exploitation frameworks.
Dalfox / XSSer / kxss
High-speed parameter scanners, payload encoders, and automated XSS framework executors.
SSRFmap / Gopherus
SSRF automated exploit engines mapping internal database sockets via gopher payloads.
Interactsh / Burp Collaborator
Out-of-Band (OOB) server interactors to check for SSRF and blind injection triggers.
Autorize / AuthMatrix / Agartha
Authorization and session permission comparison tools targeting IDOR and path traversal.
Tplmap / SSTImap
Automated Server-Side Template Injection scanners to exploit template execution flows.
LFISuite / Kadimus / liffy
LFI (Local File Inclusion) scanners and log poisoning automation exploit utilities.