
burpsuite-copy-as-xmlhttprequest
BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

XSS payloads designed to turn alert(1) into P1

Image Payload Creating/Injecting tools

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

Injects PHP payloads into JPEG images for web application exploitation, bypassing GD library image processing to achieve remote code execution.

Embed and hide any file in an HTML file

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…

A more useful CSRF PoC generator on Burp Suite

Course enrolments allowed privilege escalation from teacher role into manager role to RCE

Python script to exploit CVE-2020-14321 - Moodle 3.9 - Course enrollments allowed privilege escalation from teacher role into manager role to RCE.

Dompdf RCE PoC Exploit - CVE-2022-28368

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 | XSS to RCE

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…

POC Exploit written in Ruby