
jwt-hack
JSON Web Token Hack Toolkit

JSON Web Token Hack Toolkit

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Fix host header error in zaproxy