
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Dracos Linux ( www.dracos-linux.org ) is the Linux operating system from Indonesian

[CVE-2019-8389] An exploit code for exploiting a local file read vulnerability in Musicloud v1.6 iOS Application

CVE Description

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

Wing FTP Server RCE via Lua Injection

Proof-of-concept exploit for a cross-site scripting (XSS) vulnerability in Microsoft Outlook for iOS, enabling email-based spoofing attacks and…

CTT-Enhanced iOS Safari Exploit (based on CVE-2025-43529)

CVE-2024-4577 RCE PoC

Proof-of-concept exploit for CVE-2024-25733 demonstrating address bar spoofing in ARC Browser on iOS/iPadOS using JavaScript-based navigation…

CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability

Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module

webkit_refraction.js (The 33-Layer WebGL Payload) This JavaScript payload uses the \alpha constant to create a high-frequency "Memory Shiver." It…

Docker-based lab environment for studying CVE-2024-4577, a PHP-CGI argument injection vulnerability, with Apache and PHP 8.1.2 in CGI mode.