
ktor-cve-2023-45612-poc
Ktor XXE Injection Proof-of-Concept (CVE-2023-45612)

Ktor XXE Injection Proof-of-Concept (CVE-2023-45612)

Unauthenticated Form Submission Unique ID Modification

Sensitive Data exposure

An alternative solution(as a Magento 2 extension) to fix the XXE vulnerability CVE-2024-34102(aka Cosmic Sting). If you cannot upgrade Magento or…

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…


SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course settings. Discovered by - Rivek…

Public Disclosure

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or…

Cybersecurity lab demonstrating Apache CVE-2021-41773 path traversal vulnerability with vulnerable server simulation, scanner, and security reporting.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…


This demo application partially covers the vulnerability CVE-2024-38828