
purpleteam-s2-containers
Stage two containers
Tools for testing, exploiting, and securing web applications and APIs.

Stage two containers

TLS checking component of purpleteam

Server scanning component of purpleteam

Application scanning component of purpleteam

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads an ASP.NET webshell for authorized security testing.

Mass scanner for Joomla Helix3 CVE-2026-49049 that uploads PHP test payloads via com_ajax and detects executed (RCE) or raw PHP responses.

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

A Proof of Concept for the CVE-2021-46398 flaw exploitation


Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

A Dockerized Redash instance that is vulnerable to CVE-2021-21239

Poc of log4j2 (CVE-2021-44228)

Apache HTTP Server (2.4.49) üzerinde CVE-2021-42013 zafiyetini (Path Traversal & RCE) simüle eden Docker tabanlı sızma testi laboratuvarı.


A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.