
Inject-PHP-to-JPG-Using-Jhead
PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Tools for get offsets and adding patch for support i386

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit for remote command execution in Golang go get command.

poc for CVE-2009-5147

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

CLI to generate PHP filter chains for remote code execution via controlled include/require parameters. Produces complex iconv-based filter bypasses…

Get your data from the resource section manually, with no need for windows apis

Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing.

Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions

Malleable C2 profiles for Cobalt Strike

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

CLI wrapper for MSFvenom that streamlines payload creation with profile management, automated listener generation, and organized output for…

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

Proof-of-concept exploit for CVE-2021-38666, a Windows Remote Code Execution vulnerability. Demonstrates exploitation techniques for security testing…

Exploit for Ivanti Automation Manager CVE-2022-44569

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…