
Cybersecurity-Capstone-Project
Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

CVE-2025-59390 and ThreadLocalRandom Inverse

Exploit for Apache Druid Embedded Javascript Remote Code Execution (CVE-2021-25646), Python.

A proof-of-concept for the CVE-2021-25646, which allows for Command Injection

Python exploit for Apache Druid remote code execution (CVE-2021-25646) with reverse shell and command execution capabilities.

CVE-2021-25646 Apache Druid remote code execution detection and exploitation tool. Supports single and batch target scanning with command execution…

A go-exploit for Apache Druid CVE-2023-25194

Collections of my POCs for android vendor CVEs

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

Batch PoC scanner for CVE-2021-34045 (Druid unauthorized access). Supports single URL and file-based mass testing.

Apache Druid LoadData 任意文件读取漏洞 / Code By:Jun_sheng

Python exploit for Apache Druid remote code execution vulnerability CVE-2021-25646, enabling command injection via crafted HTTP requests.

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

CVE-2021-36749 Docker 漏洞复现

Apache Druid 任意文件读取

Proof-of-concept exploit for CVE-2021-36749, demonstrating SSRF via Druid's HTTP InputSource to read local files. Useful for security testing and…

Proof-of-concept exploit for unauthenticated SQL injection in online-shopping-system via the proId parameter, enabling data extraction from MySQL…