
CVE-2019-20372
Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

exploit CVE-2024-40725 (Apache httpd) with

Grammar-based HTTP/1 fuzzer with mutation ability

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

Proof-of-concept exploit for CVE-2023-25690 HTTP Request Smuggling in Apache mod_proxy. Includes lab environment with Docker, BurpSuite walkthrough,…

Http request smuggling vulnerability scanner

Proof-of-concept exploit for CVE-2019-20372: HTTP request smuggling via nginx error_page directive, enabling access to hidden resources.

Proof-of-concept exploit for CVE-2022-22536, demonstrating HTTP request smuggling and cache poisoning against SAP NetWeaver servers to compromise…

Proof-of-concept exploit for HTTP request smuggling vulnerability CVE-2020-25613, demonstrating chunked transfer encoding parsing bypass to poison…

CLI tool to detect HTTP Request Smuggling vulnerabilities using time-delay analysis with built-in CL.TE and TE.CL payloads for automated security…

Proof-of-concept for CVE-2021-40346, demonstrating HTTP request smuggling in HAProxy via integer overflow, with Docker-based environment to bypass…

Proof-of-concept exploit for CVE-2021-40438, an SSRF vulnerability in Apache HTTP Server, demonstrating request smuggling and internal network access.

Proof-of-concept exploit for CVE-2021-40346, an integer overflow in HAProxy enabling HTTP request smuggling and potential access control bypass.

Python-based HTTP request smuggling and desync testing tool that detects CL.TE and TE.CL vulnerabilities using configurable mutation payloads and…

PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

Proof-of-concept exploit for CVE-2020-35669 demonstrating HTTP request smuggling and header injection in Dart's http package via crafted method…