
CVE-2021-29447
CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8

CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8
cups-root-file-read.sh | CVE-2012-5519

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ImageMagick Arbitrary Read Files - CVE-2022-44268

📜 Scrape targeted wordlists for password cracking using CSS selectors

📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️

PoC scripts to exploit LFR (Local File Read) via PHP filters chain oracle (php://filter), especially for CTF purposes or the exploit of…

Monitor linux processes without root permissions


Linux enumeration tool for pentesting and CTFs with verbosity levels

Automatic Service Enumeration Script

This tool aims at automating the identification of potential service running behind ports identified manually either through manual scan or services…

A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security…

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Multi-threaded network reconnaissance tool that automates service enumeration, port scanning, and information gathering for penetration testing and…

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

Discover hidden debugging parameters and uncover web application secrets