
PDFJS
Wargame exploiting CVE-2024-4367 in PDF.js for educational vulnerability analysis and exploitation practice.

Wargame exploiting CVE-2024-4367 in PDF.js for educational vulnerability analysis and exploitation practice.
CVE-2019-19470 exploit replication with source code, WinDbg commands, PEB modification, and decompilation examples for educational red team training.

Docker-based lab demonstrating CVE-2017-8291 (GhostButt) exploitation via Python PIL/Pillow EPS image processing, with a vulnerable web application…

WordPress Plugin HTML Author Bio description XSS

Educational exploit script for CVE-2024-32002 (Git RCE) with automated setup, designed for CTF environments and security training.

Step-by-step CTF walkthrough demonstrating CVE-2019-9053 SQL injection exploitation and GTFOBins-based privilege escalation on a CMS Made Simple…


This is an exercise built around CVE-2021-3560

CTF for HDE 64 students at See Security College. Exploit a JWT (web part) & CVE-2021-3156 (LPE part).

PoC and mitigation for CVE-2019-9787 (WordPress XSS/CSRF/RCE). Demonstrates sanitization fixes, HttpOnly cookies, and hash-based CSRF defense with…

In this project, I documented a detailed penetration testing process targeting Apache HTTP Server vulnerabilities, specifically CVE-2021-41773 and…

CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523

Bai cuoi ky CVE-2022-24644

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

Solution for BFS Ekoparty challenge 2019

CVE-2021-21300 exploit implementation for network security coursework at NYCU. Includes shell scripts for vulnerability demonstration and penetration…

C++ challenge repository exploring Control Flow Guard (CFG) bypass techniques for Windows binary exploitation research.