
nano
Nano is a family of PHP web shells which are code golfed for stealth.

Nano is a family of PHP web shells which are code golfed for stealth.

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

Scanner and exploit tool for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution on Windows systems. Includes…

PoC for CVE-2025-34030 sar2html 'plot' parameter RCE

Exploit for CVE-2023-36845, a PHP environment variable manipulation vulnerability in Juniper SRX/EX, enabling unauthenticated remote code execution…

PHP poc, exploit for CVE-2025-9074

Proof-of-concept exploit for vBulletin pre-auth remote code execution vulnerabilities (CVE-2020-17496, CVE-2019-16759) via widget PHP template…

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

FuelCMS 1.4.1 Command Injection/Remote Code Execution.

CVE-2022-0944 Remote Code Execution Exploit

CVE-2026-6279: Avada (Fusion) Builder <= 3.15.2 – Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode…

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.

Customized this for my own use

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

Small PHP shell, Controlled by Python Client , connecting over protocol method

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.