
http-stalling-detector
Detect HTTP stalling attacks like slowloris with Bro

Detect HTTP stalling attacks like slowloris with Bro

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

Gophish with Malicious Attachment and HTTP redirect support

HTTP Web Server probing

Nuclei template for detecting CVE-2024-4577 PHP CGI argument injection vulnerability, enabling automated RCE testing via crafted HTTP requests and…

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Scanner and proof-of-concept for CVE-2025-62168, detecting Squid Proxy information disclosure that leaks HTTP authentication credentials.

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

Docker lab reproducing the complete CVE-2026-75650 StyleSmuggler unauthenticated HTTP RCE and validating Adobe VULN-39341.

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

Detailed write-up and proof of concept for CVE-2023-41717, demonstrating bypass of Zscaler proxy file download/upload restrictions via HTTP Range…

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise…

Python proof-of-concept for CVE-2022-1386, an unauthenticated SSRF in Fusion Builder WordPress plugin, demonstrating file read via crafted HTTP…

A flaw was found in pki-core. Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows…

Verified PoC and analysis for CVE-2026-21962, an access-control bypass in Oracle HTTP Server/WebLogic Proxy Plug-in via URI normalization…