


Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

CVE-2022-29221 Proof of Concept Code - Smarty RCE

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Hooked browser communication over MQTT

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c