
AdminSnatcher
Let's Snatch The Admin Panel Of Any Website In Seconds.

Let's Snatch The Admin Panel Of Any Website In Seconds.

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

Exploit script for CVE-2025-49132 that retrieves database credentials from vulnerable Pterodactyl panels via unauthenticated arbitrary file read,…

Python exploit for CVE-2026-55579, an unauthenticated RCE in Pheditor via hardcoded default credentials. Executes commands and uploads files through…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Exploits vulnerabilities in popular IP cameras (CCTV, GoAhead, Netwave) to disclose admin passwords. Supports single targets, file-based lists, and…

Exploits known vulnerabilities in popular routers (D-Link, Zyxel, TP-Link, Cisco, Huawei) to extract admin credentials, with support for single…

Ruby-based LDAP enumeration tool for internal penetration tests. Automates user, computer, and group discovery, password spraying, LAPS retrieval,…

Proof-of-concept exploit and detailed writeup for CVE-2020-15906, an authentication bypass in Tiki Wiki CMS Groupware 16.x-21.1 allowing…

Proof-of-concept exploit for CVE-2024-28000, a privilege escalation vulnerability in LiteSpeed Cache WordPress plugin, allowing unauthenticated…

Python exploit for CVE-2020-1472 (Zerologon) that checks, exploits, and restores domain controller machine account passwords, enabling DCSync and…

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

Python exploit for CVE-2025-47227 targeting ScriptCase pre-authentication password reset vulnerability (CVSS 9.8) to gain unauthorized admin access.

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

Multithreaded WordPress brute-force tool that tests admin credentials against a list of sites using configurable threads, timeouts, and verbose…

Fast WordPress default credential checker: uses common username/password pairs to detect weak admin accounts.