
cheetah
a very fast brute force webshell password tool

a very fast brute force webshell password tool

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell…

Highly configurable script for dictionary/spray attacks against online web applications.

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

Exploit script for JumpServer password reset vulnerability CVE-2023-42820, with automatic verification code calculation and password modification.

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

Confluence Hardcoded Password POC

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

Python exploit for CVE-2019-14314: authenticated SQL injection in NextGEN Gallery 3.2.10 WordPress plugin, extracting password hashes from the…

CVE-2022-40032: Simple Task Managing System - 'login' and 'password' SQL Injection (Unauthenticated)

Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

Python exploit for CVE-2019-9053 SQL injection in CMS Made Simple 2.2.10 with password hash cracking and user enumeration capabilities.

Exploit for CVE-2022-1162: hardcoded password bypass in GitLab CE/EE OmniAuth accounts, enabling unauthorized login with a known credential.

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.