
PySQLRecon
Offensive MSSQL toolkit written in Python, based off SQLRecon

Offensive MSSQL toolkit written in Python, based off SQLRecon

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Blind noSQL injection case study lab based on CVE-2018-3783

MAximo SQL Injection Time Based - Oracle DB

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

A python library to automate time-based blind SQL injection

Proof-of-concept exploit for CVE-2022-22980 targeting Spring Data MongoDB. Demonstrates remote code execution via crafted MongoDB queries. Requires…

PoC for CVE-2026-2005

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

ZenoMinder Blind SQL Injection PoC

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…