
Tools for testing, exploiting, and securing web applications and APIs.


Plugin to fix security vulnerability CVE-2023-40626 in Joomla 3.10.12

Simple brute force tool for Telkom Indonesia's ZTE F609 routers

Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898

POC script for CVE-2023-26035 (zoneminder 1.36.32)


Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

Repository contains description for CVE-2023-35793

POC CVE-2018-14714

Python script that sends CVE-2021-44228 log4j payload requests to url list

exploit SQL injection ELEX WooCommerce Google Shopping

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

A short demo of CVE-2021-44228

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…