
SharpExchange
C# Tool to interact with MS Exchange based on MS docs

C# Tool to interact with MS Exchange based on MS docs

Spoof emails from any of the +2 Million domains using MailChannels (DEFCON 31 Talk)

Initial Access and Post-Exploitation Tool for Entra ID and M365 with a browser-based GUI

Phishing with a fake reCAPTCHA



Scripts to clone CA certificates for use in HTTPS client attacks.

CamJacking is a tool designed for use in human penetration testing tool. It is intended to simulate potential security threats by testing the…

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

A Windows Remote Administration Tool in Visual Basic with UNC paths

Read more at Medium

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)


(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail