
jsql-injection
Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Windows Oracle Database Attack Toolkit

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).


Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

Proof-of-concept exploits for three vulnerabilities in Syncfusion file managers: directory traversal leading to arbitrary file read/write/delete, and…

Open-source, cross-platform, multi-purpose security auditing tool

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Real-time monitoring and slowlog analysis for Valkey and Redis databases with anomaly detection, ACL auditing, and Prometheus metrics export.

SQLWinds - SQL Server Security Assessment & Post-Exploitation Toolkit

CVE-2022-40032: Simple Task Managing System - 'login' and 'password' SQL Injection (Unauthenticated)

Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

Proof of Concept (PoC) for SQL Injection in Xhibiter NFT Marketplace 1.10.2 (Collections Endpoint). Discovered by Sohel Yousef.