Occamsec / CVE-2023-2825
GitLab CVE-2023-2825 PoC. This PoC leverages a path traversal vulnerability to retrieve the /etc/passwd file from a system running GitLab 16.0.0.
☆142Updated last year
Alternatives and similar repositories for CVE-2023-2825:
Users that are interested in CVE-2023-2825 are comparing it to the libraries listed below
- VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)☆231Updated last year
- CVE Collection of jQuery UI XSS Payloads☆118Updated 2 years ago
- ☆110Updated last year
- CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC☆119Updated last year
- CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.☆49Updated 2 years ago
- A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.☆110Updated 3 weeks ago
- Zimbra <9.0.0.p27 RCE☆100Updated 2 years ago
- Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)☆89Updated 2 months ago
- Time Based SQL Injection in Zabbix Server Audit Log --> RCE☆115Updated 9 months ago
- exploit for f5-big-ip RCE cve-2023-46747☆204Updated 4 months ago
- VMWare Aria Operations for Networks (vRealize Network Insight) Static SSH key RCE (CVE-2023-34039)☆96Updated last year
- POC for CVE-2022-47966 affecting multiple ManageEngine products☆126Updated 2 years ago
- pdf exploit 集成☆210Updated 7 months ago
- CVE-2022-41852 Proof of Concept (unofficial)☆75Updated 2 years ago
- Ghostscript command injection vulnerability PoC (CVE-2023-36664)☆117Updated last year
- Burp Suite's extension to scan and crawl Single Page Applications☆102Updated last year
- Endpoints Explorer is a Python script that employs multiple bypass rules to discover sensitive endpoints☆83Updated 8 months ago
- ☆103Updated 2 years ago
- Exploit for the vulnerability CVE-2024-43044 in Jenkins☆170Updated 4 months ago
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)☆75Updated 8 months ago
- DHCP Server Remote Code Execution impact: 2008 R2 SP1 до Server 2019☆70Updated last year
- CVE-2023-0669 GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to des…☆100Updated 10 months ago
- phpMyAdmin XSS☆116Updated 3 months ago
- ☆47Updated last year
- tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp☆79Updated last month
- CVE-2024-3400-RCE☆86Updated 9 months ago
- [PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)☆88Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆84Updated last year
- CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server☆88Updated 2 years ago
- ☆149Updated 7 months ago