
xepor
Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

A proof-of-concept script to conduct a phishing attack abusing Microsoft 365 OAuth Authorization Flow

Python script that acts like the original sudo binary to fool users into entering their passwords

Super organized and flexible script for sending phishing campaigns

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

PowerShell toolkit for remote template injection attacks and defense. Injects malicious links into Office Word documents for phishing, with…

CVE-2018-25031 tests

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Additional exploits for XSS in Cisco ASA devices discovered by PTSwarm

Stored XSS via CSRF in Beetel 777VR1 Router

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

Persistent XSS on Comtrend AR-5387un router

【Teedy 1.11】Account Takeover via XSS

This repository presents a proof-of-concept of CVE-2024-50677

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…