This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive server files via the MediaController. Intended for authorized security auditing and educational research only.
☆28May 10, 2026Updated 4 months ago
Alternatives and similar repositories for CVE-2024-46987
Users that are interested in CVE-2024-46987 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.☆19Feb 4, 2026Updated 7 months ago
- Proof of Concept for CVE-2025-24367☆38Dec 8, 2025Updated 9 months ago
- A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction…☆49Dec 7, 2025Updated 9 months ago
- Unauthenticated RCE in ZoneMinder Snapshots - Poc Exploit☆24May 7, 2024Updated 2 years ago
- CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused…☆17Aug 4, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Proof of Concept for chaining CVE-2025-6018 (PAM/Polkit Active Session Bypass) and CVE-2025-6019 (libblockdev SUID Mount Flaw) to achie…☆16Feb 9, 2026Updated 7 months ago
- Import custom queries into BloodHound CE from a legacy BloodHound JSON file.☆10Mar 22, 2024Updated 2 years ago
- ☆30Sep 8, 2025Updated last year
- Manage your sdks and emulators in a light and simplified way using a webui.☆13Mar 14, 2026Updated 6 months ago
- Bruteforce Keepass databases (KDBX 4.x format)☆166Jul 16, 2024Updated 2 years ago
- Proof of Concept for CVE-2025-31161 / CVE-2025-2825☆48Apr 8, 2025Updated last year
- A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1☆20Mar 19, 2024Updated 2 years ago
- Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and S…☆11Apr 9, 2022Updated 4 years ago
- Credentials manager companion to the pre-set Exegol history file☆19Aug 30, 2026Updated 3 weeks ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Pentest report framework without data send☆19Sep 23, 2025Updated 11 months ago
- Advanced Tool To Scan And Exploit Local File Inclusion (LFI) Vulnerabilities☆43Mar 24, 2026Updated 5 months ago
- CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass☆17Jun 4, 2026Updated 3 months ago
- react2shell CVE-2025-55182 PoC☆31Dec 7, 2025Updated 9 months ago
- Python script to execute commands via Erlang/OTP Distribution Protocol☆15Feb 6, 2024Updated 2 years ago
- A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132☆17Jun 22, 2025Updated last year
- Pyload RCE with js2py sandbox escape☆18Oct 26, 2024Updated last year
- Not meant to replace how you read or write, but to offer a different lens. It doesn’t interpret text like AI chatbots do; instead, it bre…☆10Jun 15, 2025Updated last year
- ☆11Nov 5, 2018Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- HTTP Headers Security Cheat Sheet☆12Sep 25, 2021Updated 4 years ago
- PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.☆22Aug 22, 2025Updated last year
- A Nmap script optimized for Hack the Box and CTFs☆17Feb 22, 2021Updated 5 years ago
- Fast-track Azure offensive security toolkit designed for CARTP certification and CTF competitions. Automated enumeration, credential extr…☆28Dec 5, 2025Updated 9 months ago
- SNES Map and Tile Editor☆19Jan 19, 2023Updated 3 years ago
- A scanner for the FortiNet vulnerability CVE-2025-64446☆31Nov 18, 2025Updated 10 months ago
- ☆11Jun 19, 2024Updated 2 years ago
- Python script for extracting and decrypting Group Policy Preferences passwords☆26May 28, 2021Updated 5 years ago
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆35Mar 28, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Tool for enumerate subdomains by Brute-force, or by using different options while grabbing results.☆14Sep 7, 2023Updated 3 years ago
- My Reverse Shell Cheat Sheet☆14Mar 2, 2022Updated 4 years ago
- An enhanced Rust variant of Gatttool☆24Jun 30, 2026Updated 2 months ago
- Decrypt mRemoteNG passwords☆74May 10, 2022Updated 4 years ago
- ☆16Apr 2, 2024Updated 2 years ago
- Normalizer for honeypot data.☆11Dec 6, 2023Updated 2 years ago
- This repository contains the setup from Paradigm CTF blockchain challenges based on the original repository. We've introduced new featur…☆51Oct 4, 2025Updated 11 months ago