Web Application
Commix
Automated command-injection exploitation.
webrce
commix — terminal
$ commix -u 'https://site/ping?host=127.0.0.1'What it does
Commix finds and exploits OS command-injection vulnerabilities in web apps, automating payloads and dropping shells. A focused complement to broader web scanners.
Common use cases
- •Exploit command injection in web forms that pass user input to system shell commands.
- •Test file-upload and file-download parameters for OS command injection flaws.
- •Rapidly evaluate command-injection vectors across hundreds of web application endpoints.
Key features
- •Supports time-based, file-based, and out-of-band command-injection detection.
- •Automatically grades injection difficulty and selects the appropriate payload.
- •Generates reverse-shell payloads for Windows and Linux targets.
- •Works in combination with Burp Suite and Zap proxy requests.
Source
https://github.com/commixproject/commix ↗More Web Application tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →