
CVE-2025-59213
Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

Unauthenticated SQL injection exploit for Microsoft Configuration Manager (SCCM) 2503, enabling arbitrary SQL execution on the site database via the…

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

Proof-of-concept exploit for CVE-2025-24999, demonstrating privilege escalation in Microsoft SQL Server via the MS_DatabaseManager role.

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

In-target C# post-exploitation tool for Microsoft SQL Server (MS SQL / MSSQL) traversing linked-server chains of any depth with cascading login…

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

Practical MSSQL penetration testing cheat sheet covering enumeration, linked-server pivoting, privilege escalation, persistence, and command…

MSDAT: Microsoft SQL Database Attacking Tool

mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection