Web
Wordpress
Reverse Shell #1 - Edit existing Plugin
git clone https://github.com/pentestmonkey/php-reverse-shell.git
cp php-reverse-shell/php-reverse-shell.php .
subl php-reverse-shell.php 
Reverse Shell #2 - Upload Plugin
TomCat
Common usernames and passwords
Reverse Shell


Spring Boot
Reverse Shell


See CMDS from page source

CGI-Bin
Scanning

Shell

Change request type






WebDav Cadvaer
XXE Injection
Exploiting XXE - In-Band
Exploiting XXE - Out-of-Band
SSRF + XXE
XML-RPC
Check if it is enabled

View Files
XSS
Reflected XSS
Stored XSS
Dom-Based XSS
XSS - Steal JVT












CSRF
Last updated