This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated users to read sensitive server files via the MediaController. Intended for authorized security auditing and educational research only.
☆27May 10, 2026Updated 2 months ago
Alternatives and similar repositories for CVE-2024-46987
Users that are interested in CVE-2024-46987 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.☆18Feb 4, 2026Updated 5 months ago
- Proof of Concept for CVE-2025-24367☆37Dec 8, 2025Updated 7 months ago
- Config files for my GitHub profile.☆14Jan 18, 2025Updated last year
- CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused…☆17Aug 4, 2025Updated 11 months ago
- A Proof of Concept for chaining CVE-2025-6018 (PAM/Polkit Active Session Bypass) and CVE-2025-6019 (libblockdev SUID Mount Flaw) to achie…☆17Feb 9, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Import custom queries into BloodHound CE from a legacy BloodHound JSON file.☆10Mar 22, 2024Updated 2 years ago
- Manage your sdks and emulators in a light and simplified way using a webui.☆13Mar 14, 2026Updated 4 months ago
- Bruteforce Keepass databases (KDBX 4.x format)☆158Jul 16, 2024Updated 2 years ago
- A proof of concept of the path traversal vulnerability in the python AioHTTP library =< 3.9.1☆20Mar 19, 2024Updated 2 years ago
- Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and S…☆11Apr 9, 2022Updated 4 years ago
- Credentials manager companion to the pre-set Exegol history file☆17Jun 24, 2026Updated 3 weeks ago
- Pentest report framework without data send☆19Sep 23, 2025Updated 9 months ago
- LimeSurvey Authenticated RCE☆24Jul 16, 2023Updated 3 years ago
- CVE-2023-28432 POC☆15Mar 24, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass☆17Jun 4, 2026Updated last month
- A customized version of spacehuhns Deauther for the esp8266 Wifi module. This folder contains the modified Deauther itself long with 3d o…☆12Jan 27, 2020Updated 6 years ago
- react2shell CVE-2025-55182 PoC☆31Dec 7, 2025Updated 7 months ago
- A mullti-purpose LDAP/Kerberos tool written in Rust.☆15Updated this week
- Follina (CVE-2022-30190) is a Microsoft Office zero-day vulnerability that has recently been discovered. It’s a high-severity vulnerabili…☆12May 14, 2023Updated 3 years ago
- Generate 1337speak based password dictionaries☆13Jul 27, 2018Updated 7 years ago
- Ansible role to deploy Lynis, a security audit tool☆13Nov 2, 2023Updated 2 years ago
- Python script to execute commands via Erlang/OTP Distribution Protocol☆15Feb 6, 2024Updated 2 years ago
- A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132☆17Jun 22, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Not meant to replace how you read or write, but to offer a different lens. It doesn’t interpret text like AI chatbots do; instead, it bre…☆10Jun 15, 2025Updated last year
- ☆11Nov 5, 2018Updated 7 years ago
- HTTP Headers Security Cheat Sheet☆12Sep 25, 2021Updated 4 years ago
- A post-exploitation tool to decrypt SolarPutty's sessions files☆37Dec 8, 2022Updated 3 years ago
- PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.☆22Aug 22, 2025Updated 10 months ago
- A Nmap script optimized for Hack the Box and CTFs☆16Feb 22, 2021Updated 5 years ago
- A scanner for the FortiNet vulnerability CVE-2025-64446☆31Nov 18, 2025Updated 8 months ago
- Fast-track Azure offensive security toolkit designed for CARTP certification and CTF competitions. Automated enumeration, credential extr…☆26Dec 5, 2025Updated 7 months ago
- ☆11Jun 19, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Gdb pwndbg for PE debug☆19May 12, 2026Updated 2 months ago
- some sploits☆19Sep 20, 2024Updated last year
- Python script for extracting and decrypting Group Policy Preferences passwords☆26May 28, 2021Updated 5 years ago
- Tool for enumerate subdomains by Brute-force, or by using different options while grabbing results.☆14Sep 7, 2023Updated 2 years ago
- My Reverse Shell Cheat Sheet☆14Mar 2, 2022Updated 4 years ago
- ☆11Apr 2, 2024Updated 2 years ago
- Analysis of Istanbul Shopping Malls☆12Apr 23, 2024Updated 2 years ago