
wraith
Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

A collection of selenium tests that might aid it takeover of a selenium node

Small backdoor using cookie.

Phase C&C Blind SQL Injection

Malleable C2 profiles for Cobalt Strike

A Windows Remote Administration Tool in Visual Basic with UNC paths

LSTAR - CobaltStrike Translated to EN

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

使用burp自动检测CVE-2025-55182 Next.js RCE 漏洞

weaponized tool for CVE-2020-17144

rust noob tried write easy exploit code with rust lang

Proof-of-concept exploit for CVE-2024-29973, a command injection vulnerability in Zyxel NAS devices. Executes arbitrary OS commands via a crafted…

Exploit for CVE-2020-15778(OpenSSH vul)

A PoC for CVE-2025-24813

Automated Python exploit for CVE-2023-30258, a command injection in Magnus Billing System v7. Sends crafted GET request to icepay.php to execute…

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injection through the Webmin's File Manager feature

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Command Injection through the Webmin's File Manager feature