
Joomla-CMS-Full-Lifecycle-Pentest
A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

This is the exploit of CVE-2019-17240.

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

cve-2016-16113

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Bludit 3.9.2 - Auth Bruteforce Bypass CVE:2019-17240 Refurbish In bash

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Exploit for CVE-2024-46987 path traversal in Camaleon CMS enabling arbitrary file download and automated SSH key extraction via brute-force.

Bludit 3.9.2 - Remote command execution - CVE-2019-16113

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…