Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-34030-PoC — PoC for CVE-2025-34030 sar2html 'plot' parameter RCE | Kitploit
Tools/GitHubGitHub/hackertyperabuser/cve-2025-34030-poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubhackertyperabuser/cve-2025-34030-poc

CVE-2025-34030-PoC

PoC for CVE-2025-34030 sar2html 'plot' parameter RCE

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
10 years agoNot yet reviewed

CVE-2025-34030 - sar2html 'plot' parameter RCE

CVSS: 10.0 Critical
Vulnerability: OS Command Injection
Programming Language: PHP
Exploit Code: Python

References:

  • https://nvd.nist.gov/vuln/detail/CVE-2025-34030
  • https://www.vulncheck.com/advisories/sar2html-command-injection

Description

sar2html version <= 3.2.1 contains an unauthenticated OS Command Injection vulnerability via the plot parameter in index.php (index.php?plot=; <command>) the output of the vulnerability is displayed in the application's interface after execution, "select # host" contains command output.

Proof of Concept

Demo Video

Download Tool