
CVE-2025-63420
Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

Advisory for CVE-2025-65742 — Newgen OmniDocs LDAP Admin BFLA

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

Exploit for Zabbix SAML SSO bypass (CVE-2022-23131) enabling unauthorized admin access by forging session cookies.

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Automated exploit for CVE-2020-6287 targeting SAP NetWeaver AS JAVA authentication bypass. Creates admin users via LM Configuration Wizard.…

Proof-of-concept exploit for CVE-2024-0566, a post-authenticated time-based SQL injection in Smart Manager 8.27.0 WordPress plugin. Demonstrates…

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

Proof-of-concept exploit for CVE-2024-0399, a post-authenticated time-based SQL injection in WooCommerce Customers Manager 29.4, targeting…

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.