
uc_browser_poc_CVE-2022-1364
Proof of concept for CVE-2022-1364 against Alibaba's UC Browser

Proof of concept for CVE-2022-1364 against Alibaba's UC Browser

Chromium Browser DoS Attack via document.title Exploitation

This Python script exploits a vulnerability (CVE-2024-21388) in Microsoft Edge, allowing silent installation of browser extensions with elevated…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

The Browser Exploitation Framework Project

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Browser extension for tracking, inspecting, and exploiting cross-document postMessage vulnerabilities with replay and cross-origin exploit simulation…

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Proof-of-concept exploit code for Firefox CVEs (2022-1802, 1529, 2200) targeting version 100.0.1 on Windows, demonstrating browser vulnerability…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Security training for the apps you actually ship. Open your browser and start hacking.

Exploit for CVE-2022-4262, a Chromium browser vulnerability. Includes references to official bug report, in-the-wild exploit analysis, and root cause…

Automated container orchestration tool for Browser-in-the-Browser (BITB) phishing attacks, enabling red teams to scale multi-target infrastructure…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

Some Generic Browser Exploits (For Educational Purposes Only)