
vendor-android-cves
Collections of my POCs for android vendor CVEs

Collections of my POCs for android vendor CVEs

Apache Druid LoadData 任意文件读取漏洞 / Code By:Jun_sheng

A proof-of-concept for the CVE-2021-25646, which allows for Command Injection

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

Proof-of-concept exploit for unauthenticated SQL injection in online-shopping-system via the proId parameter, enabling data extraction from MySQL…

CVE-2025-59390 and ThreadLocalRandom Inverse

Apache Druid 远程代码执行;检测脚本

A go-exploit for Apache Druid CVE-2023-25194

Proof-of-concept exploit for CVE-2021-36749, demonstrating SSRF via Druid's HTTP InputSource to read local files. Useful for security testing and…

Exploit for CVE-2021-25646 Apache Druid RCE via crafted HTTP POST request to the sampler endpoint, with embedded payload delivery and Snort detection…

CVE-2021-36749 Docker 漏洞复现

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

Python exploit for Apache Druid remote code execution (CVE-2021-25646) with reverse shell and command execution capabilities.

Proof-of-concept for a reflected cross-site scripting (XSS) vulnerability in Hotel Druid 3.0.2, demonstrating arbitrary JavaScript execution via…

CVE-2021-37832 - Hotel Druid 3.0.2 SQL Injection Vulnerability - 9.8 CVSS 3.1

Batch PoC scanner for CVE-2021-34045 (Druid unauthorized access). Supports single URL and file-based mass testing.

CVE-2021-25646 Apache Druid remote code execution detection and exploitation tool. Supports single and batch target scanning with command execution…