
CVE-2024-44871
Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…

Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…

PHP shells that work on Linux OS, macOS, and Windows OS.

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

Proof-of-concept exploit for CVE-2025-24801, an LFI-to-RCE vulnerability in GLPI 10.0.17. Automates login, enables PHP uploads, and uploads a reverse…

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

Python PoC script exploiting an arbitrary file upload vulnerability in Best House Rental Management System 1.0 to upload a PHP web shell and execute…

Python exploit for CVE-2023-45878 targeting Gibbon LMS 25.0.1. Uses arbitrary file write to upload a PHP web shell and execute a PowerShell reverse…

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

PHP 8.1.0-dev Backdoor System Shell Script

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Exploit for CVE-2020-24186 in WordPress wpDiscuz 7.0.4 that uploads a reverse PHP shell for remote code execution.

Shell script exploit for CVE-2019-16279 that triggers a denial-of-service via memory corruption by sending excessive CRLF sequences to an HTTP server.