
CVE-2025-51458-exp
CVE-2025-51458 - DB-GPT Pre-Auth SQL Injection PoC

CVE-2025-51458 - DB-GPT Pre-Auth SQL Injection PoC

Proof-of-concept for a time-based blind SQL injection vulnerability in the takeassessment2.php endpoint of CloudClassroom-PHP-Project 1.0,…

Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db

Proof-of-concept exploit for time-based blind SQL injection in Bacula-Web's jobfiles endpoint, using pg_sleep() delays to extract PostgreSQL version…

Proof-of-concept exploit for an SQL injection vulnerability in Doubo ERP 1.0, enabling remote attackers to extract sensitive database information.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods…

Proof-of-concept exploit for CVE-2023-49496, demonstrating SQL injection in UCServer via the /login/wwx_corpInfo/ endpoint to extract sensitive…

Webrun <= 3.6.0.42 SQLi

PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)

Proof-of-Concept exploit for CVE-2025-32429 (SQL Injection in PHP PDO prepared statements) – for educational and security research purposes only

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

🛠 Exploit the CVE-2025-14847 MongoDB vulnerability to reveal sensitive information through crafted zlib-compressed packets and real-time output.

Educational case study of the MOVEit Transfer SQL injection breach (CVE-2023-34362) by Cl0p ransomware group, covering attack timeline, exploitation,…

Public advisory for CVE-2025-50341 in Axelor

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

Nexter <= 2.0.3 - Authenticated (Subscriber+) SQL Injection via 'to' and 'from'

Environnement de démonstration pour la vulnérabilité CVE-2021-43008 d’Adminer : observer l’impact réel et tester des mesures de mitigation.