This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive server files via the MediaController. Intended for authorized security auditing and educational research only.
☆28May 10, 2026Updated 3 months ago
Alternatives and similar repositories for CVE-2024-46987
Users that are interested in CVE-2024-46987 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.☆19Feb 4, 2026Updated 6 months ago
- Python script to exploit Privilege Escalation in Camaleon CMS.☆15Feb 1, 2026Updated 6 months ago
- Unauthenticated RCE in ZoneMinder Snapshots - Poc Exploit☆24May 7, 2024Updated 2 years ago
- CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused…☆17Aug 4, 2025Updated last year
- A Proof of Concept for chaining CVE-2025-6018 (PAM/Polkit Active Session Bypass) and CVE-2025-6019 (libblockdev SUID Mount Flaw) to achie…☆16Feb 9, 2026Updated 6 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Import custom queries into BloodHound CE from a legacy BloodHound JSON file.☆10Mar 22, 2024Updated 2 years ago
- ☆29Sep 8, 2025Updated 11 months ago
- Manage your sdks and emulators in a light and simplified way using a webui.☆13Mar 14, 2026Updated 5 months ago
- Scanner de vulnerabilidades Web.☆15Sep 6, 2015Updated 10 years ago
- Bruteforce Keepass databases (KDBX 4.x format)☆165Jul 16, 2024Updated 2 years ago
- A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1☆20Mar 19, 2024Updated 2 years ago
- Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and S…☆11Apr 9, 2022Updated 4 years ago
- Credentials manager companion to the pre-set Exegol history file☆19Jun 24, 2026Updated 2 months ago
- Pentest report framework without data send☆19Sep 23, 2025Updated 11 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- LimeSurvey Authenticated RCE☆25Jul 16, 2023Updated 3 years ago
- CVE-2023-28432 POC☆15Mar 24, 2023Updated 3 years ago
- Advanced Tool To Scan And Exploit Local File Inclusion (LFI) Vulnerabilities☆42Mar 24, 2026Updated 5 months ago
- A mullti-purpose LDAP/Kerberos tool written in Rust.☆15Jul 17, 2026Updated last month
- Generate 1337speak based password dictionaries☆13Jul 27, 2018Updated 8 years ago
- Python script to execute commands via Erlang/OTP Distribution Protocol☆15Feb 6, 2024Updated 2 years ago
- Not meant to replace how you read or write, but to offer a different lens. It doesn’t interpret text like AI chatbots do; instead, it bre…☆10Jun 15, 2025Updated last year
- HTTP Headers Security Cheat Sheet☆12Sep 25, 2021Updated 4 years ago
- PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.☆22Aug 22, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Fast-track Azure offensive security toolkit designed for CARTP certification and CTF competitions. Automated enumeration, credential extr…☆27Dec 5, 2025Updated 8 months ago
- Repository for Ludus french templates☆27Jun 28, 2026Updated 2 months ago
- obfuscation that aims to not stand out☆22Mar 27, 2022Updated 4 years ago
- ☆11Jun 19, 2024Updated 2 years ago
- Gdb pwndbg for PE debug☆19Aug 2, 2026Updated 3 weeks ago
- some sploits☆19Sep 20, 2024Updated last year
- Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable…☆34Mar 28, 2026Updated 5 months ago
- My Reverse Shell Cheat Sheet☆14Mar 2, 2022Updated 4 years ago
- Decrypt mRemoteNG passwords☆74May 10, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Burp Suite extension which performs checks for cross-domain scripting against the DOM, subresource integrity checks, and evaluates Java…☆27Mar 23, 2022Updated 4 years ago
- Information gathering tool using OSINT and AI☆17Nov 21, 2024Updated last year
- Analysis of Istanbul Shopping Malls☆12Apr 23, 2024Updated 2 years ago
- This utility smart contact can be used to build DAPP which can lock LP Tokens or any BEP20 or ERC20 Tokens (Depends on deployment chain) …☆10Sep 30, 2021Updated 4 years ago
- CVE-2024-53691☆15Jan 13, 2025Updated last year
- study https://github.com/n132/Libc-GOT-Hijacking☆15Dec 7, 2023Updated 2 years ago
- JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793☆11Apr 24, 2024Updated 2 years ago