
CVE-2021-46067
CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

CVE-2018-25031 tests


an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

xll windows reverse shell

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

A simple POC (CVE-2018-25031

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

Simple PoC in PowerShell for CVE-2023-23397

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

An forensics tool to help aid in the investigation of spoofed emails based off the email headers.

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…


ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.