
CVE-2024-34568
In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

A Python module to bypass Cloudflare's anti-bot page.

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

Python exploit for CVE-2023-35885 targeting CloudPanel v2.0.0–v2.3.0. Injects a webshell via a crafted serialized cookie to achieve remote code…

Exploit script for CrushFTP authentication bypass (CVE-2025-2825) using crafted Authorization header and CrushAuth cookie to gain unauthorized access.

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Passive, read-only remote detection tool for CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect. Fingerprints PAN-OS…

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

Proof-of-concept exploit for CVE-2025-45250, an SSRF vulnerability in MrDoc's validate_url function, allowing authenticated attackers to make…

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

CVE-2025-45250 POC

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…