
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0
Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Automated exploit for Ghost CMS CVE-2023-40028 that authenticates to the admin API, uploads a symlinked ZIP, and reads arbitrary host files from the…

Active Directory relay attack detection and enumeration tool. Scans for NTLM relay opportunities, detects CVE-2025-33073, CVE-2025-54918,…

Proof-of-concept script demonstrating CVE-2023-40028 Local File Inclusion in Ghost CMS via symlink file upload, enabling authenticated attackers to…

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

Python-based proof-of-concept exploit for CVE-2023-40028, a symlink upload vulnerability in Ghost CMS enabling authenticated arbitrary file read via…

Blind SQL injection exploit for Ghost CMS (CVE-2026-26980) targeting unauthenticated Content API to extract credentials, API keys, and database…

Proof-of-concept exploit for CVE-2023-40028 enabling authenticated arbitrary file read in Ghost CMS via symlink upload. Includes interactive shell…

Proof-of-concept exploit for CVE-2023-40028, an arbitrary file read vulnerability in Ghost CMS, allowing authenticated users to read host files via…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.

Android post-exploitation framework leveraging ADB for remote device access, shell control, and automated exploitation during penetration testing…

Proof of concept demonstrating authenticated symlink upload in Ghost CMS leading to arbitrary file read via CVE-2023-40028.

A shared library wrapper with additional checks for vulnerable functions gethostbyname2_r gethostbyname_r (GHOST vulnerability)

Unauthenticated SQL injection proof-of-concept for Ghost CMS Content API (CVE-2026-26980) with Docker lab and boolean-based database extraction.

Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security

CVE-2015-0235 EXIM ESTMP GHOST Glibc Gethostbyname() DoS Exploit/PoC