
CVE-2002-0347
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root,…

Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root,…

Proof-of-concept exploit for CVE-2019-20372: HTTP request smuggling via nginx error_page directive, enabling access to hidden resources.

Multithreaded vulnerability validator for Apache Struts 2 (CVE-2017-5638) that scans thousands of endpoints via HTTP header injection to detect…

Proof-of-concept exploit for CVE-2023-38545, a curl heap buffer overflow. Includes SOCKS5 proxy and HTTP server to trigger the vulnerability and…

Exploit for Apache HTTP Server 2.4.49 path traversal and remote code execution vulnerability (CVE-2021-41773), enabling LFI and RCE on vulnerable…

Proof-of-concept exploit for CVE-2025-29927, demonstrating a middleware authentication bypass in self-hosted Next.js applications via crafted HTTP…

Proof-of-concept exploit for CVE-2024-25175: reflected XSS via HTTP response splitting in Kickidler Server before 1.107.0, with CVSS 6.1 and…

Dockerized proof-of-concept for Apache HTTP Server path traversal and RCE (CVE-2021-41773), including build instructions and curl-based exploitation…

Exploit for Apache HTTP Server path traversal and file disclosure vulnerability CVE-2021-42013, enabling unauthorized access to files on vulnerable…

Proof-of-concept exploit for CVE-2020-3187 targeting Cisco ASA/FTD session password disclosure via crafted HTTP cookie header.

Proof-of-concept exploit for HTTP request smuggling vulnerability CVE-2020-25613, demonstrating chunked transfer encoding parsing bypass to poison…

Proof-of-concept exploit for CVE-2024-51358, a server-side request forgery (SSRF) vulnerability in Heimdall 2.6.1, enabling remote HTTP requests to…

Python exploit script for CVE-2018-1306 in Apache Pluto 3.0.0, enabling malicious file upload via HTTP method tampering to achieve remote code…

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Proof-of-concept for CRLF injection in E-Staff v5.1, demonstrating HTTP response splitting and header manipulation for security testing.

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…