
strutszeiro
Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)

Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

A standalone Blind XSS Script.

Proof of Concept (PoC) for CVE-2024-7014 (EvilVideo) Exploit

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Proof-of-concept exploit for CVE-2023-3047 SQL injection vulnerability in TMT Lockcell. Demonstrates manual exploitation using cURL and Burp Suite to…

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

CVE-2017-7679 POC SCRIPT BY LORDWARE....

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda routers. Sends crafted unauthenticated POST requests to trigger a crash and…

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).