
CVE-2009-5147
poc for CVE-2009-5147

poc for CVE-2009-5147
LSTAR - CobaltStrike Translated to EN

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

CLI wrapper for MSFvenom that streamlines payload creation with profile management, automated listener generation, and organized output for…

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Exploit for remote command execution in Golang go get command.

Tools for get offsets and adding patch for support i386

Python codes of my blog.

Executes position independent shellcode from an encrypted zip

A technique of hiding malicious shellcode via Shannon encoding.

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.

CVE-2023–4220 Exploit

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…