
CVE-2023-23397
CVE-2023-23397 C# PoC

CVE-2023-23397 C# PoC

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

cve-2024-21413

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Spoof file icons and extensions in Windows

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123…

Proof-of-concept exploit for CVE-2017-5223 demonstrating arbitrary file read via PHPMailer's attachment and email content injection.

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

PoC for CVE-2025-22131

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure