Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-35813-PoC — An exploit for the Sitecore Remote Code Execution Vulnerability | Kitploit
Tools/GitHubGitHub/bagheeraaltered/cve-2023-35813-poc
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubbagheeraaltered/cve-2023-35813-poc

CVE-2023-35813-PoC

An exploit for the Sitecore Remote Code Execution Vulnerability

View Repository
5216 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Sitecore Remote Code Execution Vulnerability

CVE: 2023-35813 (discovered by @mwulftange) CVSS Score: 9.8 Severity: Critical

This is the fantastic blog post from the researchers that found it: https://code-white.com/blog/exploiting-asp.net-templateparser-part-1/

Figure out what command you want to use, and put it in a file called command.txt then run command.py to encode it

after it's encoded run the exploit.py script with the hostname of the target as the arg

Download Tool