
CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC
PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…


Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

Proof-of-concept exploit for CVE-2024-53677 (S2-067), an Apache Struts2 file upload logic bypass enabling remote code execution via crafted filename…

Exploit for eLabFTW 1.8.5 (CVE-2019-12185) enabling arbitrary file upload and remote code execution via EntityController. Generates a PHP shell in…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have…

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

PoC exploit generator for CVE-2008-4654, a stack-based buffer overflow in VLC Media Player via crafted .ty+ files. Generates malicious payload file…

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

A simple tool for bypassing file upload restrictions.

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to…

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…