
cve-2025-4664
PoC and Setup for CVE-2025-4664

PoC and Setup for CVE-2025-4664

Proof-of-concept for unauthenticated SQL injection in Hotel and Tourism Reservation System 1.0, demonstrating database extraction via the tour…

A PoC script for demonstrating CVE 2025-64458, found in Django, potential DoS in `HttpResponseRedirect`/`HttpResponsePermanentRedirect` on Windows.

This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical…

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

SQL injection via unsanitized QuerySet.order_by() input

SQL injection in QuerySet.annotate(), aggregate(), and extra()


Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction

Nexus Repository 3 Path Traversal (CVE-2024-4956)

This is the data that powers the PortSwigger URL validation bypass cheat sheet.

it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port,…

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

Demonstrates SSRF exploitation via URL parser differential between urllib.parse and requests, including vulnerable service and PoC exploit script.