
ezXSS
Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.

Proof-of-concept exploit for CVE-2021-26855, demonstrating SSRF in Microsoft Exchange Server to access backend services and extract user information.

Joomla! < 4.2.8 - Unauthenticated information disclosure

IBM Maximo Asset Management is vulnerable to Information Disclosure via XXE Vulnerability (CVE-2020-4463)

Proof-of-concept exploit for CVE-2022-24990 combining information disclosure and remote code execution in a single chain, targeting web applications.

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

Local File Inclusion (LFI) in FHEM 6.0 allows an attacker to include a file, it can lead to sensitive information disclosure.

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Go-based exploit tool for CVE-2021-41277, a Metabase sensitive information disclosure vulnerability enabling local file inclusion and environment…

Information and scripts for the confluence CVE-2022-26134

Python exploit for CVE-2021-38314 targeting unauthenticated information disclosure in the Gutenberg Template Library & Redux Framework WordPress…

CVE-2023-38035 Recon oriented exploit, extract company name contact information

CVE-2018-12031 | LFI in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file, it can lead to sensitive information disclosure,…

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the…

This application utilized the Self Registration feature to create a rogue agent that then dumps ApplianceConfiguration settings which may or may not…

This is a project about attacking and gathering information of the windows machines which is connected in the same network by using java programs