
crlfi-scanner
CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Zeek package detecting Apache HTTP Server path traversal/RCE exploits (CVE-2021-41773, CVE-2021-42013) with payload capture and server header…

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Zeek package for detecting Log4j CVE-2021-44228 exploit attempts via HTTP header payloads, LDAP Java class downloads, and second-stage Java class…

TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header…

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

NetScaler (Citrix ADC) CVE-2023-3519 Scanner

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of…

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

Proof-of-concept exploit for CVE-2020-3187 targeting Cisco ASA/FTD session password disclosure via crafted HTTP cookie header.

Here is a simple but effective exploit for CVE-2025-29927.

Stored XSS via User-Agent in Admin Order View in PhocaCart

Proof-of-concept exploit for CVE-2020-35669 demonstrating HTTP request smuggling and header injection in Dart's http package via crafted method…

Proof-of-concept for CRLF injection in E-Staff v5.1, demonstrating HTTP response splitting and header manipulation for security testing.