
CVE-2021-43650
Webrun <= 3.6.0.42 SQLi
database-securityexploitationpenetration-testing+3

Webrun <= 3.6.0.42 SQLi
A collection of web pages vulnerable to SQL injection flaws

Proof-of-concept exploit for CVE-2025-24999, demonstrating privilege escalation in Microsoft SQL Server via the MS_DatabaseManager role.

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

This lab simulates CVE-2019-9193 - PostgreSQL COPY FROM PROGRAM RCE