
VulnHub-DC1-Writeup
VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Docker-based vulnerable WordPress lab with Python exploit demonstrating pre-auth route confusion and SQL injection chain (CVE-2026-63030 +…

PHP-based CTF engine for hosting capture-the-flag competitions with arbitrary challenges, scoreboards, hints, team management, and admin console.…

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and…

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

Proof-of-concept exploit for CVE-2026-8181, an unauthenticated authentication bypass in Burst Statistics WordPress plugin (3.4.0-3.4.1.1) leading to…

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

Stored XSS exploit for Coolify (CVE-2025-34157) enabling admin session takeover via malicious project deletion. Includes PoC, CVSS 9.4, and…

Proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin, enabling web shell deployment for penetration…

User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

CTF challenge simulating a multi-step attack chain exploiting Moodle CVE-2025-26529, including SSRF, stored XSS, session hijack, and privilege…

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…