
Admin-Panel_Finder
A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

A burp suite extension that enumerates infrastructure and application admin interfaces (OTG-CONFIG-005)

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Rubbish SQLI that requires Admin

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

Hackable HTTP proxy for resiliency testing and simulated network conditions

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Extends BloodHound to collect and ingest Active Directory relationships from macOS hosts, including logged-in users, admin groups, SSH/VNC/AppleEvent…

Detection artifact generator that verifies cPanel/WHM authentication bypass (CVE-2026-41940) and demonstrates RCE via CRLF injection, targeting WHM…

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

WooCommerce Payments: Unauthorized Admin Access Exploit

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in Ultimate Member WordPress plugin versions below 2.6.7. Intended for…

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…