
web2py-e94946d-CVE-2016-3957
web2py/web2py @ e94946d

web2py/web2py @ e94946d
General purpose TLS and crypto library

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

Self-hosted email alias masking service using Postfix and Telegram bot to create disposable addresses for signups, with full control over email…

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Technical analysis and proof-of-concept for CVE-2026-21858, an authentication bypass and RCE in n8n, demonstrating LFI, session forgery, and full…

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full…

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

CVE-2025-8517 proof-of-concept demonstrating session fixation in Vvveb CMS v1.0.6.1, enabling full administrative account takeover via arbitrary…