
CVE-2025-57819-FreePBX-RCE2Root
Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Ruby-based MySQL client for penetration testing with SQL shell, database management, file read/write, PHP command/reverse shells, and a Linux MySQL…

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Proof-of-concept exploit for CVE-2026-2005, a heap-based buffer overflow in PostgreSQL pgcrypto enabling arbitrary memory read/write and privilege…

SQL Injection Vulnerability in Vehicle Management System 1.0 - 1.3

Proof-of-concept exploit for CVE-2016-6662 demonstrating SQL injection to remote root shell on MySQL servers. Includes video demonstration and…

Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access,…

Proof-of-concept exploit for CVE-2024-27956 SQL injection in ValvePress Automatic plugin. Creates admin users in WordPress to achieve remote code…

Unauthenticated SQL injection to root RCE exploit for FreePBX CVE-2025-57819, chaining SQLi, cron webshell, and incron fwconsole hook for full…

Exploit for CVE-2023-6654 targeting PHPEMS cookie deserialization to perform SQL injection, enabling password modification and privilege escalation…

Black-box penetration test of a Drupal 7 server demonstrating a full kill chain: SQL injection (CVE-2014-3704) to RCE, reverse shell, and privilege…

Proof-of-concept exploit for CVE-2021-32099 targeting Pandora FMS 742. Demonstrates SQL injection to escalate privileges and achieve remote code…

Step-by-step walkthrough of CVE-2024-42327 exploitation targeting Zabbix, demonstrating SQL injection, privilege escalation via API, and remote code…

Automates SQL injection in WordPress wp-automatic plugin to create a new administrator user, exploiting CVE-2024-27956 for direct database…

Step-by-step CTF walkthrough demonstrating CVE-2019-9053 SQL injection exploitation and GTFOBins-based privilege escalation on a CMS Made Simple…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…