m-sec-org / EZ

EZ是一款集信息收集、端口扫描、服务暴破、URL爬虫、指纹识别、被动扫描为一体的跨平台漏洞扫描器。
690 stars 28 forks source link

SQL injection,XSS detection need some optimization #3

Closed khanjanny closed 6 months ago

khanjanny commented 6 months ago

Hi there i was testing EZ performance, and it seems it have some great extra features for testing web applications or API whatever you say. although I tested EZ on different test applications like pikachu and it seems SQL injection,XSS is not yet properly implemented or are somehow missing detection of the vulnerability please take a look.

I was using you --listen option for pushing requests from burp to EZ.

zitn commented 6 months ago

Thank you very much for your comments, we have added the optimization suggestions you mentioned to the development plan, so please look forward to our future version.