
CVE-2014-3704
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

Python 3 exploit for CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple < 2.2.10, extracting admin credentials and…

Python 3 exploit for Pluck CMS 4.7.13 file upload restriction bypass, enabling authenticated admin to upload a PHP webshell and achieve remote code…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin…

Exploit for CVE-2020-29204 targeting XXL-JOB distributed task scheduling framework, demonstrating remote code execution via unauthenticated access to…

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Proof of Concept and Security Advisory for XSS vulnerability in the FD602GW-DX-R410 fiber router’s admin console (firmware V2.2.14). Includes…

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in the Ultimate Member WordPress plugin. Intended for educational…

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

Bash exploit for CVE-2015-1397 (Magento Shoplift) that injects crafted SQL payloads to create an admin user on vulnerable Magento stores.

Python exploit for CVE-2023-32315, a path traversal in Openfire's admin console, allowing unauthenticated access to restricted pages. Includes Docker…

Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…