
CVE-2024-39929
POC to test CVE-2024-39929 against EXIM mail servers

POC to test CVE-2024-39929 against EXIM mail servers

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

POC BLH Magelang CSIRT 2026 by babyrootkid

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Proof of concept for CVE-2020-7247 for educational purposes.

LetsDefend SOC336 case study on CVE-2025-21298

Lab write-up analyzing CVE-2024-21413 Outlook Moniker Link exploitation, NetNTLMv2 credential leakage via SMB, detection with YARA/Wireshark, and…

Documentation of my hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.

Exploit for the CVE-2023-23397

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…

Exim Honey Pot for CVE-2019-10149 exploit attempts.

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

C# PoC exploit for CVE-2023-23397 that sends malicious Outlook meeting invites with a UNC path trigger for NTLM credential theft.

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…