๐Ÿ’‰ Vulnerability Exploitation

This category collects exploit engines designed to automate SQL injection dumps, XSS injection testing, Command Injection shells, LFI/RFI parsing, and SSTI/SSRF mapping.

Tool Catalog

Select a tool below to view detailed specifications, cheatsheets, or definitions.

๐Ÿ’พ

SQLmap

Automated SQL injection discovery, DBMS database extractor, and shell execution suite.

View Wiki โ†’
๐ŸŒ

XSStrike

Context-aware Cross-Site Scripting fuzzer utilizing script reflection analyzers.

View Wiki โ†’
๐Ÿš

Commix

Automated Command Injection Exploiter capable of generating shell environments.

View Wiki โ†’
๐Ÿ’พ

Ghauri / BBQSQL

Advanced alternative blind SQL injection detection and exploitation frameworks.

๐Ÿงช

Dalfox / XSSer / kxss

High-speed parameter scanners, payload encoders, and automated XSS framework executors.

โ›“๏ธ

SSRFmap / Gopherus

SSRF automated exploit engines mapping internal database sockets via gopher payloads.

๐Ÿ“ก

Interactsh / Burp Collaborator

Out-of-Band (OOB) server interactors to check for SSRF and blind injection triggers.

๐Ÿ›ก๏ธ

Autorize / AuthMatrix / Agartha

Authorization and session permission comparison tools targeting IDOR and path traversal.

๐Ÿน

Tplmap / SSTImap

Automated Server-Side Template Injection scanners to exploit template execution flows.

๐Ÿ“‚

LFISuite / Kadimus / liffy

LFI (Local File Inclusion) scanners and log poisoning automation exploit utilities.


๐Ÿ”— Back to Toolkit