
CVE-2023-51764
Postfix SMTP Smuggling - Expect Script POC

Postfix SMTP Smuggling - Expect Script POC

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…


An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows…

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

Root-Level RCE via OS Command Injection in Ivanti Sentry

Enumerates all HTML elements and attributes that can leak HTTP requests, enabling testing of browsers, web proxies, and email clients for unintended…

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).


CVE-2023-5561-PoC

Querytool is an OSINT framework based on Google Spreadsheet. With this tool you can perform complex search of terms, people, email addresses, files…

Repository of attack and defensive information for Business Email Compromise investigations

It’s an OSINT reconnaissance poc powered by Local LLMs (Ollama). You can feed it an email, domain, or IP, and it automatically performs multiple…

Template Injection in Email Templates leads to code execution on Jira Service Management Server