
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

CLI tool to scan for and exploit insecure Firebase databases, supporting mass vulnerability scanning, custom JSON payload injection, and URI path…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

PoC exploit for CVE-2021-22146 that dumps Elastic ECE databases (versions 7.10.0 to 7.13.3) during internal penetration tests.

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

SQL injection exploit for CVE-2025-26794 in Exim 4.98. Automated data extraction via time-based blind SQLi. For authorized penetration testing only.

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

Proof-of-concept tool demonstrating MITM attack to strip SSL/TLS from MySQL connections, exploiting CVE-2015-3152 for network penetration testing.

Automatic SQL injection and database takeover tool

🔥 A powerful MongoDB auditing and pentesting tool 🔥

MSDAT: Microsoft SQL Database Attacking Tool

chusa - 注射 - the new generation of sqlmap
