
CVE-2024-42009-PoC
CVE-2024-42009 Proof of Concept

CVE-2024-42009 Proof of Concept

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

The Outlook HTML Leak Test Project

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Zeroday Microsoft Exchange Server checker (Virtual Patching checker)

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

PoC exploit code for CVE-2021-26855

Proof-of-concept exploit for CVE-2021-33766 (ProxyToken) authentication bypass in Microsoft Exchange Server. Supports single and batch target…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。