
vendor-android-cves
Collections of my POCs for android vendor CVEs

Collections of my POCs for android vendor CVEs

Novel-plus-install-v3.5.3-Druid Unauthorized access

Proof-of-concept exploit for unauthenticated SQL injection in online-shopping-system via the proId parameter, enabling data extraction from MySQL…

Proof-of-concept exploit for CVE-2020-1958, an LDAP injection vulnerability in Apache Druid 0.17.0, enabling user enumeration and LDAP attribute…

CVE-2021-25646 Apache Druid remote code execution detection and exploitation tool. Supports single and batch target scanning with command execution…

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

A go-exploit for Apache Druid CVE-2023-25194

CVE-2021-37832 - Hotel Druid 3.0.2 SQL Injection Vulnerability - 9.8 CVSS 3.1

Exploit for CVE-2021-25646 Apache Druid RCE via crafted HTTP POST request to the sampler endpoint, with embedded payload delivery and Snort detection…

CVE-2025-59390 and ThreadLocalRandom Inverse

CVE-2021-36749 Docker 漏洞复现

A proof-of-concept for the CVE-2021-25646, which allows for Command Injection

Python exploit for Apache Druid remote code execution (CVE-2021-25646) with reverse shell and command execution capabilities.

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

Apache Druid LoadData 任意文件读取漏洞 / Code By:Jun_sheng

Exploit for Apache Druid Embedded Javascript Remote Code Execution (CVE-2021-25646), Python.

Apache Druid 任意文件读取

Apache Druid 远程代码执行;检测脚本