
beef
The Browser Exploitation Framework Project

The Browser Exploitation Framework Project

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Spoof file icons and extensions in Windows

cve-2024-21413

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…


PoC for CVE-2025-22131

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Use a Fake image.jpg to exploit targets (hide known file extensions)

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…