

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in…

This project aims at re-analyzing and PoC about CVE-2023-33733. Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a…


This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

An example of CVE-2020-7740