
WebView2-Cookie-Stealer
Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Extraction of iMessage Data via XSS

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart