
sqlancer
Automated testing to find logic and performance bugs in database systems

Automated testing to find logic and performance bugs in database systems

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

POCs to demonstrate CVE-2026-42167 in ProFTPD

Specifications and open-source platforms for self-sovereign, encrypted real estate data management with blockchain-inspired verification, enabling…

CVE-2023-45503 Reference

Security research project — SQL Injection vulnerability exploitation and mitigation

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

CVE-2023-31702 is an authenticated SQL Injection vulnerability discovered in MicroWorld Technologies eScan Management Console version 14.0.1400.2281.


Proof-of-concept demonstrating authenticated SQL injection in College Management System 1.0 via the 'course_code' parameter, with boolean-based blind…

Technical disclosure and proof-of-concept for SQL injection in PuneethReddyHC event-management v1.0, detailing affected endpoint, payloads, and…

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…

A critical SQL Injection vulnerability (CVE-2025-25964) discovered in the School Information Management System v1.0

Proof-of-concept exploit for CVE-2021-21311, an SSRF vulnerability in Adminer database management tool versions 4.0.0–4.7.8. Includes a Python…

Python-based proof-of-concept exploit for CVE-2025-5840 targeting file upload vulnerabilities in database management systems, enabling remote command…