Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-40444--CABless — Modified code so that we don´t need to rely on CAB archives | Kitploit
Tools/GitHubGitHub/edubr2020/cve-2021-40444--cabless
Payload GenerationExploitationWeb Application ExploitationPapers & ResearchLearning & Education
GitHubedubr2020/cve-2021-40444--cabless

CVE-2021-40444--CABless

Modified code so that we don´t need to rely on CAB archives

View Repository
1041914 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-40444--CABless version

Update: Modified code so that we don´t need to rely on CAB archives the file "index.html" that triggers payload execution will contain 1 line of code only, inside 'script' tag:

An article in PDF format is provided.

Update: link to video demo -> https://www.youtube.com/watch?v=V9XD3VboEcU

Note: The sample RAR file does NOT contain a Word document designed to exploit the vulnerability as I have taken as reference one of the PoCs posted on GitHub. Instead, it just have merged WSF and RAR data to demonstrate the path described in the article so the file can be parsed as RAR and WSF (chimera).

Download Tool