Tony Harris's starred repositories
sqlalchemy
The Database Toolkit for Python
JNDI-Exploit-Kit
JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps vulnerable to JNDI Injection)
CVE-2023-20887
VMWare vRealize Network Insight Pre-Authenticated RCE (CVE-2023-20887)
CVE-2024-22120-RCE
Time Based SQL Injection in Zabbix Server Audit Log --> RCE
CVE-2024-36991
POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.
rogue-jndi
A malicious LDAP server for JNDI injection attacks
CVE-2023-21554-PoC
CVE-2023-21554 Windows MessageQueuing PoC,分析见 https://www.zoemurmure.top/posts/cve_2023_21554/
CVE-2021-40539
Exploitation code for CVE-2021-40539
CVE-2024-8504
VICIdial Unauthenticated SQLi to RCE Exploit (CVE-2024-8503 and CVE-2024-8504)
CVE-2024-23897
POC for CVE-2024-23897 Jenkins File-Read
CVE-2024-29847
Exploit for CVE-2024-29847
TLS_Extended_Master_Checker
Detection for RFC7627 Support (TLS Extended Master Secret Extension)
CVE-2024-8190
CVE-2024-8190: Ivanti Cloud Service Appliance Command Injection
CVE-2023-22527
Atlassian Confluence - Remote Code Execution
CVE-2024-8517
SPIP BigUp Plugin Unauthenticated RCE
CVE-2024-7120
⚠️⚠️ CVE-2024-7120 Command Injection Vulnerability in RAISECOM Gateway Devices
CVE-2023-51764
PoC CVE-2023-51764
CVE-2024-44849
🔥 CVE-2024-44849 Exploit
cert-headers
The list of possible HTTP headers used to store client certificate information