
CVE-2016-4437
Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key

Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.

若依4.2 (Shiro 1.4.1) Shiro-721 (CVE-2019-12422)漏洞复现环境

This is a simple Shiro-basic project .Just for pentest env

Apache Shiro CVE-2022-32532

Shiro RememberMe 1.2.4 反序列化 漏洞

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

Exploit tool for CVE-2023-46604 in Apache ActiveMQ, supporting out-of-band exploitation, custom bytecode execution, and Shiro ini configuration for…

一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.

Exploit code for CVE-2020-11989, an Apache Shiro authentication bypass vulnerability, enabling remote attackers to bypass security controls in web…
