
cpanel_xss_2023
Python-based scanner for detecting and assessing exploitability of CVE-2023-29489 XSS vulnerability in cPanel. Supports single URL, batch file input,…

Python-based scanner for detecting and assessing exploitability of CVE-2023-29489 XSS vulnerability in cPanel. Supports single URL, batch file input,…

Blind XSS callback server that captures victim cookies, local storage, and page data, then sends encrypted reports via Telegram for session hijacking.

Proof-of-concept exploit script for CVE-2017-7679, an Apache Struts remote code execution vulnerability, demonstrating exploitation for security…

Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

Scans for CVE-2024-4956, a local file inclusion vulnerability in Sonatype Nexus Repository Manager 3, with options for single URL, list input, and…

Scans for CVE-2024-24919 (Check Point Security Gateway LFI) in single or multiple URLs, with Telegram notifications and output saving for penetration…

Scanner for Apache Superset authentication bypass (CVE-2023-27524) with single URL, batch input, and Telegram notifications for security testing.

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Scans for Joomla SQL injection vulnerability CVE-2015-7297, supporting single URLs, batch input, and Telegram notifications for bug bounty hunters.

Scans Oracle WebLogic Server for CVE-2022-21371 local file inclusion, detects and exploits LFI vulnerabilities, supports batch URL scanning and…

Scanner for CVE-2023-24044, an open redirect vulnerability in Plesk Obsidian, with URL list scanning, Telegram notifications, and output to file.

Reflected XSS vulnerability scanner for cPanel CVE-2023-29489 with URL scanning, batch input, Telegram notifications, and output logging.

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Proof-of-concept exploit for CVE-2023-3047 SQL injection vulnerability in TMT Lockcell. Demonstrates manual exploitation using cURL and Burp Suite to…

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload