
Lastenzug
Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

Demonstrating Remote Code Execution Vulnerability via Pickle Serialization in ClearML

Finding Java/C# gadget chains with CodeQL

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library

CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!


CVE-2018-6574 POC : golang 'go get' remote command execution during source code build