
CVE-2020-25273
Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

cve-2023-22515的python利用脚本

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

A simple python script to grab twitter account info just by username or profile link

Unauthenticated Xerte Online Toolkits exploit. Requires knowing a valid username.

Remotely test password strength of WordPress bloging software

Exploit for CVE-2024-22274 that creates a privileged user and spawns a root SSH shell on a target host using provided credentials.

Exploit systems using older WinRAR without knowing their username (unlike other projects)

Proof-of-concept exploit for CVE-2023-23752 (Joomla 4.0.0-4.2.8) that extracts usernames and passwords via an information disclosure vulnerability.

Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

An unauthenticated PoC for CVE-2020-0796

Proof-of-concept for Active Directory username enumeration vulnerability in Hyland OnBase via login endpoint response differences, enabling…

Python tool for exploiting CVE-2021-35616

This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet…

FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523