
CVE-2025-32429-Checker
Python-based vulnerability scanner for detecting CVE-2025-32429 SQL injection in XWiki platforms. Supports single/bulk scanning, WAF detection,…

Python-based vulnerability scanner for detecting CVE-2025-32429 SQL injection in XWiki platforms. Supports single/bulk scanning, WAF detection,…

Automated SQLMap tamper suggester that tests payloads against WAF/IDS/IPS and recommends bypass techniques based on HTTP status codes, supporting…

Automated SQL injection exploitation toolkit for WordPress Contest Gallery CVE-2026-3180, featuring blind data extraction, WAF bypass, reverse shell,…

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

An automatic SQL Injection tool which takes advantage of ~DorkNet~ Googler, Ddgr, WhatWaf and sqlmap.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Manual black-box penetration test of hosting provider infrastructure using curl_cffi and Python. Identifies exposed databases, default credentials,…

A cheat sheet that contains advanced queries for SQL Injection of all types.

Burp Suite plugin providing a quick-access toolbar for SQL injection, XSS payloads, and WAF bypass testing, with built-in encoder/decoder for web…

Automatic SQL injection and database takeover tool

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Proof-of-concept exploit for authenticated SQL injection in Gandia Integra Total, demonstrating boolean-based and time-based injection techniques…

High-performance, low-maintenance Nginx module acting as a DROP-by-default WAF, blocking XSS, SQL injection, and other web attacks using simple…

Exploit for Imperva Cloud WAF bypass using gzip Content-Encoding header to evade WAF rules on HTTP POST requests. Includes detection script and…

Exploit for CVE-2021-45468, an Imperva WAF bypass.

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…