
CVE-2020-2978
Proof-of-concept exploit for CVE-2020-2978 targeting Oracle RMAN audit table point-in-time recovery bypass, enabling unauthorized database access.

Proof-of-concept exploit for CVE-2020-2978 targeting Oracle RMAN audit table point-in-time recovery bypass, enabling unauthorized database access.

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Demonstrates CVE-2024-21513 in langchain-experimental, showing arbitrary code execution via VectorSQLDatabaseChain's eval() on retrieved values.…

Proof-of-concept exploit for CVE-2024-31449, a stack buffer overflow in Redis Lua engine via bit.tohex, enabling denial-of-service and potential…

CVE-2024-45265

Proof-of-concept exploit for an authenticated SQL injection vulnerability in JFinal CMS 5.1.0, demonstrating information disclosure and potential…

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

Customer Support System 1.0 - SQL Injection Vulnerability in the "subject" Parameter During "save_ticket" Operation

Share Buttons – Social Media <= 1.0.2 - Unauthenticated SQL Injection

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Proof-of-concept for CVE-2024-50971, a SQL injection vulnerability in Itsourcecode Construction Management System 1.0, with exploitation steps and…

Exploit script for ServiceNow CVE-2024-4879 that enables unauthenticated remote code execution, with mass target scanning and database dumping…

Proof-of-concept exploit for CVE-2022-21661, a SQL injection vulnerability in WordPress Core WP_Query, demonstrating the attack and providing…

Proof-of-concept exploit for CVE-2020-2969 targeting unauthorized access to Oracle Database password hashes. Enables security researchers to test and…

Proof-of-concept for SQL injection in SourceCodester Visitor Management System 1.0 via the id parameter, allowing arbitrary SQL command execution.

Proof-of-concept for CVE-2021-39378: SQL injection in openSIS 8.0 via the str parameter in NamesList.php, enabling database extraction and blind…

Proof-of-concept exploit for SQL injection vulnerability in SourceCodester Human Resource Management System 1.0, enabling unauthenticated admin login…