
web2py-e94946d-CVE-2016-3957
web2py/web2py @ e94946d

web2py/web2py @ e94946d

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Blind noSQL injection case study lab based on CVE-2018-3783

MAximo SQL Injection Time Based - Oracle DB

Proof-of-concept exploit for CVE-2022-22980 targeting Spring Data MongoDB. Demonstrates remote code execution via crafted MongoDB queries. Requires…

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

ZenoMinder Blind SQL Injection PoC

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

chusa - 注射 - the new generation of sqlmap

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

Proof-of-concept exploit for CVE-2025-22964, a time-based blind SQL injection vulnerability in DDSN Interactive cm3 Acora CMS 10.1.1, enabling…

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the…

CVE-2022-23305 Log4J JDBCAppender SQl injection POC

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection