
Log4J-Scanner
Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.

Pcap importer for Burp

AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Burp plugin able to find reflected XSS on page in real-time while browsing on site

Burp Suite extension for extracting metadata from files

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

Remote code execution in Mediawiki Score

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Framework for identifying and exploiting out-of-band (OOB) application vulnerabilities with a custom DNS/token server, Burp Suite extension, and…

Proof of concept for CVE-2017-6640 as burp extension

Burp Suite extension to track vulnerability assessment progress

Demonstrates a local code execution exploit for Foxit PDF Reader via XFA-based PDFs, with step-by-step attack reproduction and extension to related…