
AntiWeb_testing-Suite
Suite de herramientas que sacan partido del CVE-2017-9097 (+RCE)

Suite de herramientas que sacan partido del CVE-2017-9097 (+RCE)

Password cracking utility

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made…

Exploits Python cve-2019-9053– by HackHeart

Proof-of-concept for CVE-2022-45782: predictable dotCMS password-reset tokens, with a token cracker and full exploit chain.

Proof of Concept code for exploitation of CVE-2024-38793 (Best Restaurant Menu by PriceListo <= 1.4.1 - Authenticated (Contributor+) SQL Injection)

Python exploit for CVE-2019-9053 SQL injection in CMS Made Simple 2.2.10 with password hash cracking and user enumeration capabilities.

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

Blind SQL injection brute force.

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Working Python exploit for CVE-2019-9053 with optional password cracking via wordlist. Targets web applications via HTTP URI for automated…

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

Improved code of Daniele Scanu SQL Injection exploit

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Exploit for CVE-2025-2011

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

Python 3 exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks…

Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.