
SOC_287
SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]

SOC287 - Arbitrary File Read on Checkpoint Security Gateway [CVE-2024-24919]

Proof-of-concept exploit for CVE-2025-55182 demonstrating remote code execution in Next.js via prototype pollution. Includes a pre-configured…

CVE-2025-70341: Local Privilege Escalation via TOCTOU in App-Auto-Patch

Proof-of-concept exploit for CVE-2023-0386, a Linux OverlayFS local privilege escalation vulnerability. Demonstrates how incorrect file capability…

Proof-of-concept demonstrating a local privilege escalation in sudo (CVE-2025-32463) via chroot configuration manipulation, intended for defensive…

Reproduction script for CVE-2025-48384, a git clone RCE via carriage return in submodule paths, demonstrating the vulnerability and providing a local…

PoC environment and exploit for the Apache Tomcat on Windows Remote Code Execution Vulnerability

Educational exploit for CVE-2024-21413 (Moniker Link) demonstrating Outlook RCE and NTLM credential leak via crafted hyperlinks, with detection and…

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

Docker container with a pre-configured vulnerable environment for CVE-2019-9184, designed for security testing and educational exploitation practice.

Step-by-step tutorial demonstrating how to set up a vulnerable Apache 2.4.49 environment and exploit CVE-2021-41773 path traversal using Kali Linux…

Docker-based test environment for validating CVE-2024-23113 Nuclei templates against simulated vulnerable FortiOS instances, supporting multiple…

Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465…

Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)

Educational Jupyter notebook demonstrating the Dual_EC_DRBG cryptographic backdoor (CVE-2014-8610) with NIST P-256 state recovery attack, historical…

CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.