
sparty
Sparty - MS Sharepoint and Frontpage Auditing Tool [Unofficial]
Tools for testing, exploiting, and securing web applications and APIs.

Proof-of-concept PHP 8 sandbox escape exploiting a use-after-free bug to bypass disable_functions and execute system commands on Unix-like systems.


Plex Unlocker

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

A FreeSWITCH specific scanning and exploitation toolkit for CVE-2021-37624 and CVE-2021-41157.

Facebook brute forcer script

Effortlessly browse and manage your files with ease using Tiny File Manager [WH1Z-Edition], a compact single-file PHP file manager.

WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Python PoC for CVE-2020-35846 targeting Cockpit 0.11.1

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect