
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0
Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Automated exploit for Ghost CMS CVE-2023-40028 that authenticates to the admin API, uploads a symlinked ZIP, and reads arbitrary host files from the…

Proof-of-concept script demonstrating CVE-2023-40028 Local File Inclusion in Ghost CMS via symlink file upload, enabling authenticated attackers to…

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

Python-based proof-of-concept exploit for CVE-2023-40028, a symlink upload vulnerability in Ghost CMS enabling authenticated arbitrary file read via…

Blind SQL injection exploit for Ghost CMS (CVE-2026-26980) targeting unauthenticated Content API to extract credentials, API keys, and database…

Proof-of-concept exploit for CVE-2023-40028 enabling authenticated arbitrary file read in Ghost CMS via symlink upload. Includes interactive shell…

Proof-of-concept exploit for CVE-2023-40028, an arbitrary file read vulnerability in Ghost CMS, allowing authenticated users to read host files via…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

A Directory Traversal attack (also known as path traversal) aims to access files and directories that are stored outside the intended folder.

Compile Go and C# programs into WASM-sandboxed native executables with polymorphic output, ghost profiling, and transparent Win32/macOS API bridging…

Proof of concept demonstrating authenticated symlink upload in Ghost CMS leading to arbitrary file read via CVE-2023-40028.

Unauthenticated SQL injection proof-of-concept for Ghost CMS Content API (CVE-2026-26980) with Docker lab and boolean-based database extraction.

Proof-of-concept exploit for CVE-2020-0796 (SMBv3 Ghost) with demonstration video. Enables remote code execution testing against vulnerable Windows…

Proof-of-concept exploit for a stored XSS vulnerability in Ghost CMS (CVE-2025-66849) enabling privilege escalation from Contributor to Owner via…

Python exploit for CVE-2023-40028 enabling authenticated arbitrary file read on Ghost CMS, designed for educational use and HTB machines.

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…