
sccmsqlclient
MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Proof-of-concept exploit for CVE-2024-31449, a stack buffer overflow in Redis Lua engine via bit.tohex, enabling denial-of-service and potential…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI


fsp - Firestore Database Vulnerability Scanner Using APKs

ColorOS短信漏洞,以及用户自救方案

Woo Inquiry <= 0.1 - Unauthenticated SQL Injection

RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Reproducible Docker lab for CVE-2025-25257, demonstrating SQL injection bypass and data exfiltration via HTTP Authorization header on a simulated…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Jepsen-based transactional correctness testing framework for DuckDB, detecting isolation anomalies like G2-item and SSI violations via randomized…

chusa - 注射 - the new generation of sqlmap

The script focuses on safe artifact acquisition first, followed by optional on-host analysis, and produces a portable, hashed forensic archive…