
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout
PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Deliberately vulnerable Next.js lab demonstrating CVE-2025-29927 middleware authorization bypass. Includes Dockerized app, middleware-protected admin…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

The code for personally reproducing the corresponding vulnerability

Docker-based vulnerable WordPress lab with Python exploit demonstrating pre-auth route confusion and SQL injection chain (CVE-2026-63030 +…

PHP-based CTF engine for hosting capture-the-flag competitions with arbitrary challenges, scoreboards, hints, team management, and admin console.…

Docker-based lab environment for exploiting CVE-2019-5475 and CVE-2019-15588 RCE command injection vulnerabilities in Nexus Repository Manager with…

Python exploit for CVE-2024-27198, an authentication bypass vulnerability in JetBrains TeamCity Server. Creates a new admin user on vulnerable…

Step-by-step demonstration of a local privilege escalation vulnerability in Lenovo PC Manager, exploiting weak file permissions on a system service…

CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and…

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

Demonstrates the x-middleware-subrequest header bypass in Next.js 13.4.19, allowing unauthorized access to protected routes. Includes setup, normal…

Exploit for CVE-2023-22518 in Atlassian Confluence. Provides a detailed walkthrough of the vulnerability, including environment setup, root cause…

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

Dockerized exploit environment for CVE-2024-10924, an authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1)…

Deliberately vulnerable Apache Solr application (CVE-2021-44228) for practicing Log4Shell exploitation via User-Agent, POST, and admin endpoints.…