
CVE-2023-22047---Oracle-PeopleSoft-LFI
CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Proof-of-concept exploit for CVE-2021-2175, an Oracle Database Vault metadata exposure vulnerability, demonstrating unauthorized access to sensitive…

Oracle WebLogic CVE-2022-21371

Automated exploit for CVE-2012-3153 / CVE-2012-3152

Exploit for CVE-2018-2894 targeting Oracle WebLogic Server remote code execution vulnerability, enabling unauthenticated attackers to execute…

Python exploit script for CVE-2020-14882 targeting Oracle WebLogic Server. Executes remote commands via crafted HTTP requests to unauthenticated…

PoC scripts to exploit LFR (Local File Read) via PHP filters chain oracle (php://filter), especially for CTF purposes or the exploit of…

Automated script for performing Padding Oracle attacks

Exploit for CVE-2018-3191 targeting Oracle WebLogic servers. Generates a malicious payload via RMI, deploys reverse shell classes on an HTTP server,…

Python-based exploit script for Oracle WebLogic CVE-2020-14882 unauthorized bypass RCE. Tests authentication bypass and remote code execution via…

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

Automated scanner and exploit for CVE-2019-2725 (Oracle WebLogic RCE). Reads target IPs from ip.txt, checks for vulnerability, and saves exploitable…

Proof-of-concept exploit for CVE-2019-2615 targeting Oracle WebLogic Server. Demonstrates unauthenticated path traversal via crafted HTTP requests to…

Proof-of-concept exploit for CVE-2020-14882 in Oracle WebLogic Server, demonstrating remote code execution via crafted HTTP requests to the console…

Kernel module using ftrace to block AF_ALG/AEAD requests, mitigating CVE-2026-31431 without requiring LSM BPF. Provides logging and easy compilation…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Oracle E-Business Suite <=12.2 - Authentication Bypass

This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)