
CVE-2022-46169
Unauthenticated Command Injection in Cacti <= 1.2.22

Unauthenticated Command Injection in Cacti <= 1.2.22
A demo of the Log4Shell (CVE-2021-44228) vulnerability.

Hands-on lab exercise for exploiting Log4Shell (CVE-2021-44228) with JNDI injection, LDAP referral servers, and reverse shell payloads. Includes…

Proof-of-concept exploit for Apache Spark command injection (CVE-2022-33891) with check and reverse shell modes, enabling authorized security testing.

Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

Explorations of CVE-2024-49368 + Exploit Development


A POC demo on CVE-2023-38831

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

Python exploit for CVE-2022-36804, a command injection in Atlassian Bitbucket Server and Data Center, enabling remote code execution with read…

CVE-2023-51385

Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!

Log4Shell CVE-2021-44228 Demo

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.

Reusable offensive security skills and plugins for AI agents, covering reconnaissance, exploitation, C2, payload development, and reporting across…