
ImageMagick-CVE-2022-44268-PoC
A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268

A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268

Example payload for CVE-2022-21894


CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

SnakeYAML CVE-2022-1471 exploit payload for demo

A simple application that shows how to exploit the CVE-2022-42889 vulnerability

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

CVE-2022-42475 飞塔RCE漏洞 POC

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

Verifed Proof of Concept on CVE-2022-24086

Exploit I discovered in October of 2022 with androids Package manager binary (pm) and the way it handled debugging flags, patched out by march 2023.…


CVE-2022-41852 Proof of Concept (unofficial)

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马