VulnScanners Logo

Web Application

Commix

Automated command-injection exploitation.

webrce
commix — terminal
$ commix -u 'https://site/ping?host=127.0.0.1'

What it does

Commix finds and exploits OS command-injection vulnerabilities in web apps, automating payloads and dropping shells. A focused complement to broader web scanners.

Common use cases

  • Exploit command injection in web forms that pass user input to system shell commands.
  • Test file-upload and file-download parameters for OS command injection flaws.
  • Rapidly evaluate command-injection vectors across hundreds of web application endpoints.

Key features

  • Supports time-based, file-based, and out-of-band command-injection detection.
  • Automatically grades injection difficulty and selects the appropriate payload.
  • Generates reverse-shell payloads for Windows and Linux targets.
  • Works in combination with Burp Suite and Zap proxy requests.

Source

https://github.com/commixproject/commix

More Web Application tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →