// what it is
Description
Anastasios Stasinopoulos' command-injection scanner that auto-detects results-based, blind-time-based, and file-based variants and gives you a shell on success.
// use cases
What people use it for
- Confirm command-injection findings
- Automated exploitation
// commands
The commands you'll type
Test a URL
$ commix --url='https://target/ping?host=127.0.0.1'