
BSQLinjector
Blind SQL injection exploitation tool written in ruby.

Blind SQL injection exploitation tool written in ruby.

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Simple script to automate brutforcing blind sql injection vulnerabilities

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

Exploit for CVE-2024-43468: unauthenticated SQL injection in Microsoft Configuration Manager Management Points, enabling arbitrary SQL execution and…

Proof-of-concept exploit for Fortinet FortiClient EMS SQL injection vulnerability (CVE-2023-48788). Demonstrates unauthenticated SQL injection to…

Proof-of-concept exploit for CVE-2022-0332, a SQL injection vulnerability in Moodle 3.11 to 3.11.4, with a working HTTP GET payload for…

CVE-2017-8917 - SQL injection Vulnerability Exploit in Joomla 3.7.0

A python library to automate time-based blind SQL injection

Proof-of-concept exploit for CVE-2024-2879: unauthenticated SQL injection in LayerSlider WordPress plugin (7.9.11-7.10.0). Includes scanner script…

ISR-sqlget It's a blind SQL injection tool developed in Perl.

WordPress WP_Query SQL Injection POC

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

Django QuerySet.annotate(), aggregate(), extra() SQL 注入

Tool to crawl, visualize and interact with SQL server links in a d3 graph to help in your red/blue/purple/.../risk assessments pentest hacking team…

Proof-of-concept exploit for CVE-2021-32099, a SQL injection vulnerability in Pandora FMS, demonstrating session hijacking via crafted UNION query.