
SecurityNotFound
Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2017-5638, demonstrating exploitation via crafted Content-Type…

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

JSON Web Token Hack Toolkit

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)

st2-046-poc CVE-2017-5638

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header.

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain…

Exploit for CVE-2004-1561 Icecast header overwrite buffer overflow on Windows, providing remote code execution with a reverse shell payload.