
Microsoft365_devicePhish
A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Collection of offensive red team scripts including process termination, SPF bypass for phishing, password spraying, and ColdFusion password…

Python script that acts like the original sudo binary to fool users into entering their passwords

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

Super organized and flexible script for sending phishing campaigns

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Additional exploits for XSS in Cisco ASA devices discovered by PTSwarm

Stored XSS via CSRF in Beetel 777VR1 Router

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Python exploit for CVE-2026-32201, a reflected XSS in Microsoft SharePoint Server, enabling unauthenticated spoofing and data modification via…

【Teedy 1.11】Account Takeover via XSS

This repository presents a proof-of-concept of CVE-2024-50677

Persistent XSS on Comtrend AR-5387un router

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)