
CVE-2023-27524-POC
A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files…

RFC6265-compliant cookie parsing and CookieJar management library for Node.js, with CVE-2023-26136 security patch. Supports cookie creation,…

Web Backdoor Cookie Script-Kit

Proof-of-concept exploitation steps for CVE-2024-3400, demonstrating unauthenticated command injection in Palo Alto GlobalProtect via crafted cookie…

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3).

Exploit for CVE-2019-18935 (Telerik UI) with WAF bypass via encrypted cookie payload injection and custom memory shell deployment.

Bash-based proof-of-concept tester for CVE-2026-23550. Checks WordPress modular connector login endpoints for admin cookie issuance and verifies…

Proof-of-concept exploit demonstrating an XSS vulnerability in ARD's Ajax transaction manager endpoint through unsanitized accountName input,…

Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static…

CVE-2026-5513 — Bookly ≤ 27.2 Stored XSS via Cookie

CVE-2026-5513: Bookly <= 27.2 Stored XSS via Cookie (Unauthenticated)

Proof-of-concept for a stored XSS vulnerability in Simple Content Management System PHP, demonstrating session cookie theft via unsanitized News…

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof-of-concept exploit for CVE-2025-63708, a stored XSS vulnerability in AI Font Matcher. Demonstrates session cookie theft via unsanitized font…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…