Skip to content

Automatic Prototype Pollution Exploitation #200

@edoardottt

Description

@edoardottt

The desired behavior would be having a new flag -e (-exploit) in scan input.
pphack then will try to produce a PoC URL for the exploit (e.g. XSS) based on the vulnerable technology.

Are we sure about chromedp alert box detection? maybe js detection is better...

  • WAF checks?
  • Check JSON output too.

Sub-issues

Metadata

Metadata

Assignees

Labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions