
CVE-2021-40223
XSS Vulnerability in Rittal

XSS Vulnerability in Rittal
Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated…

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156

The DCERPC only printerbug.py version

Exploit created using Python

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

A toolkit to attack Office365

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

Exploit for CVE-2024-46987

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

Rails 3 PoC of CVE-2019-5418

Test cases for broken MIME and tools to generate and process these

short view of ruby on rails properties misconfiguration

Docker-based sandbox to reproduce and test CVE-2019-5418 Ruby on Rails path traversal vulnerability via crafted Accept headers.

Ruby on Rails Phishing Framework

Docker-based lab environment for CVE-2019-5418 Ruby on Rails path traversal exploit, with PoC curl commands to read arbitrary server files via…