
CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer
PoC and internal port brute-forcer for CVE-2023-27163

PoC and internal port brute-forcer for CVE-2023-27163

Unauthenticated Arbitrary File Read via Absolute Path

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

Tool to discover external and internal network attack surface

Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through…

Python and Powershell internal penetration testing framework


Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Microsoft Network Service Fingerprinting Tool

Internal network scanner through Gluu IAM blind ssrf

Test for CVE-2000-0649, and return an IP address if vulnerable

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

Atlassian Jira XSS attack via Server Side Request Forgery (SSRF).

DejaVU - Open Source Deception Framework