
cve-2025-3248
Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Proof-of-concept exploit for CVE-2024-3400, a command injection vulnerability in Palo Alto firewalls, demonstrating file creation and remote command…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Reproduction of cve-2024-3400-panos_rce_reproduction

Meterpreter auto exploit program

Android client for Adaptix C2 framework enabling remote agent management, interactive command shells, listener control, payload generation, and…

CVE-2024-3400 : Palo Alto OS Command Injection - POC

Nuclei template and bash script for detecting and exploiting CVE-2024-3400 command injection in Palo Alto PAN-OS GlobalProtect, enabling…

Detection, analysis, and response strategies for CVE-2024-3400 exploitation attempts targeting Palo Alto PAN-OS GlobalProtect portals. Includes IOCs,…

Exploit for CVE-2024-0012 and CVE-2024-9474 targeting authentication bypass and authenticated command injection in Palo Alto PAN-OS management web…

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Vulnerabilidad de palo alto

Go-based exploit for CVE-2024-3400, enabling unauthenticated remote code execution on PAN-OS firewalls via command injection in GlobalProtect.…

Proof-of-concept exploit for CVE-2024-3400, demonstrating command injection in Palo Alto PAN-OS with a Python-based backdoor, persistence via…

Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation

Automated exploit for Chamilo command injection vulnerability (CVE-2023-34960) with auto shell upload capability for penetration testing and…

A check program for CVE-2024-3400, Palo Alto PAN-OS unauthenticated command injection vulnerability. Palo Alto 防火墙 PAN-OS 远程命令注入检测程序。

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect