
GoCD_PoC_Supply_Chain_Attack
CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Setup and exploit recreation for CVE-2022-42889 Text4Shell.

Proof-of-concept exploit for a heap buffer overflow in libpng on PS4/PS5. Generates a malicious PNG that triggers the vulnerability when opened in…


Automatic SSTI detection tool with interactive interface

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…

Spring Framework RCE (Quick pentest notes)

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

Find out a modified Cacti public exploit!

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.