
CVE-2025-48932-Invision-Community-SQLi-Exploit
Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Remotely delete access logs, Windows event logs, databases, and files on target machines using automated scanning or manual attack selection for…

Offensive MSSQL toolkit written in Python, based off SQLRecon

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Black-box penetration test of a Drupal 7 server demonstrating a full kill chain: SQL injection (CVE-2014-3704) to RCE, reverse shell, and privilege…

Step-by-step walkthrough of CVE-2024-42327 exploitation targeting Zabbix, demonstrating SQL injection, privilege escalation via API, and remote code…

Automates SQL injection in WordPress wp-automatic plugin to create a new administrator user, exploiting CVE-2024-27956 for direct database…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Windows privilege escalation tool exploiting SeImpersonate privileges via Named Pipe impersonation, supporting multiple execution methods…

Proof-of-concept exploits for CVE-2026-42167, a SQL injection vulnerability in ProFTPD's mod_sql logging pipeline enabling unauthenticated SQL…

Proof-of-concept exploit for CVE-2026-63030: unauthenticated blind SQL injection in WordPress REST batch endpoint leading to remote code execution.…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.

CLR-based toolkit for lateral movement through compromised Microsoft SQL Server via socket reuse, enabling proxy and file operations in restricted…

A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.