
Joomla-webshell-plugin
A webshell plugin and interactive shell for pentesting a Joomla website.

A webshell plugin and interactive shell for pentesting a Joomla website.

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

Collection of public proof-of-concept exploits for multiple CVEs, providing vulnerability demonstration code and references for security research and…

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

Technical analysis and detection guidance for CVE-2026-21589, a pre-auth path traversal arbitrary file access flaw in Atlassian Data Center products.

Python PoC exploiting Apache Tomcat CVE-2025-24813 partial PUT deserialization RCE, with auto variant detection, ysoserial gadget chains, and reverse…

Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated…

Proof-of-concept lab and exploit client for CVE-2026-59358, demonstrating Cloud Foundry UAA reuse of a user PKCE token as client_credentials Bearer…

Vulnerable environment of CVE-2013-2251 (S2-016) for testing

Vulnerable environment of CVE-2020-17530 (S2-061) for testing

Proof-of-concept and research material for CVE-2026-59265, a LibreOffice and OpenOffice vulnerability, intended for authorized lab testing and…

Research materials and tooling for exploiting email address parser discrepancies to bypass access controls, including fuzzers, Hackvertor tags, CSS…

HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy + Exploit Timing Attacks

CVE-2026-105221 - gist RubyGem - High - MITM - GitHub OAuth token theft

Burp Suite extension that extends active and passive scanning with checks for host header attacks, XXE, expression language injection, shellshock and…

Simple PoC for demonstrating Race Conditions on Websockets

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

A Java Burp Plugin that performs text clustering on responses to identify outliers/groups based on the actual content of the server responses, say…