
SQLRecon
A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

CVE-2026-23631 (DarkReplica) Redis Exploit

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A low-privileged user can exploit this via a crafted order_by parameter, causing time-based blind SQL injection.

Proof-of-concept for a time-based blind SQL injection vulnerability in the takeassessment2.php endpoint of CloudClassroom-PHP-Project 1.0,…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Webrun <= 3.6.0.42 SQLi

Relational database brute force and post exploitation tool for MySQL and MSSQL

A Poc for CVE-2020-24913, a SQL injection vulnerability in qcubed (all versions including 3.1.1) in profile.php via the strQuery parameter allows an…

Proof-of-concept exploit for CVE-2024-0399, a post-authenticated time-based SQL injection in WooCommerce Customers Manager 29.4, targeting…

Proof-of-concept exploit for CVE-2024-33911, a post-authenticated SQL injection vulnerability in The School Management WordPress plugin v10.3.4,…

Proof-of-concept exploit for CVE-2024-32136, a post-authenticated SQL injection in BWL Advanced FAQ Manager 2.0.3, demonstrating time-based database…

SolarWinds Orion Account Audit / Password Dumping Utility

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

PoC of CVE-2022-24707