command-injection-payload-list

Command injection examples

A collection of examples and tools to test and exploit command injection vulnerabilities in web applications.

🎯 Command Injection Payload List

GitHub

3k stars
73 watching
648 forks
last commit: about 2 years ago
Linked from 1 awesome list

applicationapplication-securitybugbountycommandcommand-injectioninjectionlinuxmacososos-injectionpayloadpayload-listsecuritysecurity-researchsecurity-testingsecurity-vulnerabilityunixvulnerabilityvulnerability-researchwindows

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
payloadbox/sql-injection-payload-listProvides a comprehensive list of SQL injection payloads and techniques5,067
payloadbox/xss-payload-listA collection of scripts and payloads designed to exploit Cross-Site Scripting (XSS) vulnerabilities in web applications.6,484
payloadbox/xxe-injection-payload-listLists examples and types of XML external entity injection payloads and attacks1,110
portswigger/command-injection-attackerAn OS command injection detection and exploitation tool that provides methodologies and software for identifying and exploiting vulnerabilities in applications.106
fuzzdb-project/fuzzdbA comprehensive toolset for identifying and exploiting application vulnerabilities through dynamic testing8,288
commixproject/commixAutomates the detection and exploitation of command injection vulnerabilities in web applications.4,647
plackyhacker/shellcode-injection-techniquesA collection of C# techniques for injecting malicious shellcode into processes450
whitel1st/docemA tool to embed malicious payloads in various document formats553
airbus-cert/invoke-bofLoads and executes a malicious payload in a Windows system using PowerShell.245
liamg/traitorA tool for automatically exploiting vulnerabilities to gain elevated privileges on Linux systems6,735
payloadbox/rfi-lfi-payload-listProvides examples and explanations of vulnerabilities in web applications545
pwntester/ysoserial.netGenerates payloads to exploit unsafe .NET object deserialization.3,260
mik0w/pallmsA collection of payloads designed to exploit vulnerabilities in large language models.70
syssec-kaist/sigover_injectorA tool that exploits weaknesses in LTE broadcast signals to inject manipulated signals without an FBS.90
offsecginger/aes-powershellcodeA PowerShell payload designed to evade detection and execute malicious commands on a target system108