Sploitus

Exploit for OS Command Injection in Gnu Bash

gitee · 2025-07-27

Exploit Code

MARKDOWN2 lines
## https://sploitus.com/exploit?id=D77F483D-BF9F-540E-A7EF-302650FCAE4A
This is an extension for Burp Suite, a web application security testing tool. The extension, named "ActiveScan++", extends Burp's active and passive scanning capabilities to identify application behavior that may be of interest to advanced testers. It includes checks for potential host header attacks, edge side includes, XML input handling, suspicious input transformation, and passive-scanner issues that only occur during fuzzing. The extension also includes checks for blind code injection via expression language, Ruby's open() and Perl's open(), and several known vulnerabilities such as CVE-2014-6271/CVE-2014-6278 'shellshock' and CVE-2015-2080, CVE-2017-5638, CVE-2017-12629, CVE-2018-11776. The extension is built using Java and is compatible with Burp Suite Professional or Enterprise.