
skyhook
A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

Extraction of iMessage Data via XSS

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies