
VulnerableDotNetHTTPRemoting
Example Vulnerable .NET HTTP Remoting

Example Vulnerable .NET HTTP Remoting

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…

Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

CVE-2023-50164 PoC Application & Exploit script

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) with a vulnerable Spring Boot application, Python exploit script, and Docker-based lab…

Python-based exploit for CVE-2021-45428, targeting a specific web application vulnerability for penetration testing and security assessment.

log4shell sample application (CVE-2021-44228)

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

Proof-of-concept exploit for CVE-2021-21315, demonstrating remote code execution in a web application framework. Intended for security testing and…

Exploit for CVE-2018-16156 targeting a remote code execution vulnerability in a web application, providing a proof-of-concept payload for security…

automate CVE-2015-9235 exploitation


Automatic SSTI detection tool with interactive interface

Proof-of-concept exploit for CVE-2023-30800, demonstrating a web application vulnerability with a Go-based payload generator for security testing and…