Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

feakk/xxxpwn

Open more actions menu

Repository files navigation

xxxpwn : XPath eXfiltration eXploitation Tool : https://github.com/feakk/xxxpwn Designed for blind optimized XPath 1 injection attacks

xxxpwn uses a variety of XPath optimizations to query custom information from a backend XML dodcument served from a location where XPath injection is present. By default it will attempt to retrieve the entire remote database, though this can be customized using a variety of options.

A number of previous discovered vulnerabilities have been provided as injection files and target scripts for ease in getting started. This includes a sample payload provided for the vulnerable application provided as part of xcat.py: https://github.com/orf/xcat

About

Advanced XPath Injection Tool

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •  
Morty Proxy This is a proxified and sanitized view of the page, visit original site.