🌐
GitHub
github.com › commixproject › commix
GitHub - commixproject/commix: Automated All-in-One OS Command Injection Exploitation Tool · GitHub
Automated All-in-One OS Command Injection Exploitation Tool - commixproject/commix
Starred by 5.8K users
Forked by 935 users
Languages   Python
🌐
GitHub
github.com › topics › command-injection
command-injection · GitHub Topics · GitHub
python command-line scanner injection remote xss cybersecurity rce sql-injection vulnerability vulnerability-detection vulnerability-scanners ssrf lfi sqlinjection command-injection xxe-injection cross-site-scripting remote-code-execution sql-injection-remote-code-execution-cross-site ... Waymap is a fast and optimized web vulnerability scanner built for penetration testers. It helps in identifying vulnerabilities by testing against various payloads. python scanner hacking waf command-line-tool bypass sqlmap exploitation-framework xss-detection sql-scanner sqlinjection command-injection lfi-exploitation ssti open-redirect-detection sqli-scanner command-injection-scanner waymap trixsec website-hacking-tool
🌐
GitHub
github.com › PortSwigger › command-injection-attacker
GitHub - PortSwigger/command-injection-attacker: SHELLING - a comprehensive OS command injection payload generator · GitHub
The purpose of creating this tool was to reach the non-trivial OS command injection cases, which stay undetected by generally known and used tools and sets of payloads.
Starred by 110 users
Forked by 28 users
Languages   Java 67.8% | PHP 27.7% | Perl 4.2% | HTML 0.3%
🌐
GitHub
github.com › z0noxz › mando.me
GitHub - z0noxz/mando.me: Web Command Injection Tool
Web Command Injection Tool. Contribute to z0noxz/mando.me development by creating an account on GitHub.
Starred by 9 users
Forked by 9 users
Languages   Python 100.0% | Python 100.0%
🌐
GitHub
github.com › swisskyrepo › PayloadsAllTheThings › blob › master › Command Injection › README.md
PayloadsAllTheThings/Command Injection/README.md at master · swisskyrepo/PayloadsAllTheThings
Based on the tool from HoLyVieR/dnsbin, also hosted at dnsbin.zhack.ca ... A polyglot is a piece of code that is valid and executable in multiple programming languages or environments simultaneously. When we talk about "polyglot command injection," we're referring to an injection payload that can be executed in multiple contexts or environments.
Author   swisskyrepo
🌐
GitHub
github.com › topics › os-command-injection
os-command-injection · GitHub Topics · GitHub
Vulnerable Web application made with PHP/SQL designed to help new web testers gain some experience and test DAST tools for identifying web vulnerabilities. Containing some of the most well-known vulnerabilities such as SQL, cross-site scripting ...
🌐
GitHub
github.com › Gaurav-Jadhav › Command-Injection
GitHub - Gaurav-Jadhav/Command-Injection: Simple Command Injection Scanner for Web Applications with the intent of automatic testing. · GitHub
Simple Command Injection Scanner for Web Applications with the intent of automatic testing. - Gaurav-Jadhav/Command-Injection
Author   Gaurav-Jadhav
🌐
GitHub
github.com › TheWation › CiCePhpbox
GitHub - TheWation/CiCePhpbox: The command injection sandbox is a tool for testing command injection vulnerabilities in web apps, in a safe environment.
The command injection sandbox is a tool for testing command injection vulnerabilities in web apps, in a safe environment. - TheWation/CiCePhpbox
Author   TheWation
🌐
GitHub
github.com › H4CK3RT3CH › commix
GitHub - H4CK3RT3CH/commix · GitHub
Commix (short for [comm]and [i]njection e[x]ploiter) is an automated tool written by Anastasios Stasinopoulos (@ancst) that can be used from web developers, penetration testers or even security researchers in order to test web-based applications ...
Author   H4CK3RT3CH
🌐
GitHub
github.com › ilmercu › Scanner-and-Command-Injection
GitHub - ilmercu/Scanner-and-Command-Injection: Vulnerabilities scanner tool · GitHub
Vulnerabilities scanner tool. Contribute to ilmercu/Scanner-and-Command-Injection development by creating an account on GitHub.
Starred by 5 users
Forked by 3 users
Languages   Python 71.6% | PHP 28.4%
Find elsewhere
🌐
GitHub
github.com › commixproject › commix › wiki › Command-Injection-Testbeds
Command injection testbeds · commixproject/commix Wiki
Automated All-in-One OS Command Injection Exploitation Tool - commixproject/commix
Author   commixproject
🌐
GitHub
github.com › swisskyrepo › PayloadsAllTheThings › tree › master › Command Injection
PayloadsAllTheThings/Command Injection at master · swisskyrepo/PayloadsAllTheThings
Based on the tool from HoLyVieR/dnsbin, also hosted at dnsbin.zhack.ca ... A polyglot is a piece of code that is valid and executable in multiple programming languages or environments simultaneously. When we talk about "polyglot command injection," we're referring to an injection payload that can be executed in multiple contexts or environments.
Author   swisskyrepo
🌐
GitHub
github.com › omurugur › OS_Command_Payload_List
GitHub - omurugur/OS_Command_Payload_List: OS Command Injection Vulnerability Payload List · GitHub
• OS Command Injection point_right https://www.owasp.org/index.php/Command_Injection
Starred by 58 users
Forked by 23 users
🌐
GitHub
github.com › w3f › injection-tool
GitHub - w3f/injection-tool: Tools, scripts and utilities for making injections. · GitHub
After installing you would replace ts-node src/index in the commands below with the injection-tool command.
Starred by 6 users
Forked by 2 users
Languages   TypeScript 92.5% | JavaScript 7.0%
🌐
GitHub
github.com › commixproject
Commix Project · GitHub
Automated All-in-One OS Command Injection Exploitation Tool · Python 5.6k 924 · commix-testbed · commix-testbed Public · A collection of web pages, vulnerable to command injection flaws · PHP 182 67 · commixproject.github.io · commixproject.github.io Public ·
🌐
GitHub
github.com › Email-Analysis-Toolkit › command-injection-tester
GitHub - Email-Analysis-Toolkit/command-injection-tester · GitHub
The command-injection-tester script allows for straightforward testing of email servers for the STARTTLS command injection vulnerability in SMTP, POP3, and IMAP.
Starred by 19 users
Forked by 3 users
Languages   Python
🌐
GeeksforGeeks
geeksforgeeks.org › linux-unix › commix-os-command-injection-and-exploitation-tool
Command Injection - GeeksforGeeks
September 25, 2025 - Good for initial surface mapping. ... exfiltrate data during tests. Commix is a free, open-source Python tool (GitHub) for detecting and exploiting command-/shell-injection flaws in web applications....
🌐
GitHub
github.com › payload-box › command-injection-payload-list
GitHub - payload-box/command-injection-payload-list: Command Injection Payload List · GitHub
A comprehensive collection of command injection payloads for security testing and penetration testing purposes.
Starred by 51 users
Forked by 7 users
🌐
GitHub
github.com › Server-Side-Injection-Tools
Server-Side-Injection-Tools · GitHub
Server-Side-Injection-Tools/Gopherus’s past year of commit activity ... Automated All-in-One OS command injection and exploitation tool.
🌐
GitHub
github.com › PortSwigger › command-injection-attacker › blob › master › README.md
command-injection-attacker/README.md at master · PortSwigger/command-injection-attacker
The purpose of creating this tool was to reach the non-trivial OS command injection cases, which stay undetected by generally known and used tools and sets of payloads.
Author   PortSwigger