
CVE-2025-26794-exploit
SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

A Python Framework For NoSQL Scanning and Exploitation

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Hunt Open MongoDB instances

An modular asset discovery framework written in python to automate the repeating manual work

mssql 终端连接工具|命令执行

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

PoC of CVE-2022-24707

MongoDB 内存泄露漏洞 (CVE-2025-14847) 检测工具

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting


Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3