
H2-database-CVE-2022-23221
Reproduces CVE-2022-23221 RCE in H2 database via malicious JDBC URL with INIT parameter, using Docker-based lab environment and Python PoC exploit…

Reproduces CVE-2022-23221 RCE in H2 database via malicious JDBC URL with INIT parameter, using Docker-based lab environment and Python PoC exploit…

Proof-of-concept exploit and technical analysis for an authenticated SQL injection vulnerability in OpenSTAManager's Stampe module, including a full…

Proof-of-concept exploit for CVE-2026-33917, a SQL injection vulnerability in OpenEMR <8.0.0.3. Includes technical analysis, vulnerable code paths,…

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

This repo contains my python script version of CVE-2025-14847 (MongoBleed)

Exploit script for CVE-2025-14847 (MongoBleed) that triggers heap memory disclosure in MongoDB by sending crafted OP_MSG packets, leaking sensitive…

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Python script to detect CVE-2024-4879 in ServiceNow instances and extract database connection details including credentials for security assessment.

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

Python tool for exploiting CVE-2021-35616

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).

Forensic tool to extract and analyze SQLite databases from rooted Android devices, generating structured XML reports for digital investigations.