
CVE-2021-41773_CVE-2021-42013
Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

Proof-of-concept exploit for CVE-2017-7529, an integer overflow vulnerability in Nginx HTTP server, enabling remote denial-of-service or potential…

Proof-of-concept exploit for CVE-2019-3980 enabling remote command execution via custom C# payload with HTTP callback for output retrieval.

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Unauthenticated RCE Flaw in Rejetto HTTP File Server (CVE-2024-23692)

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

Exploit for CVE-2018-3191 targeting Oracle WebLogic servers. Generates a malicious payload via RMI, deploys reverse shell classes on an HTTP server,…

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by…

Proof-of-concept exploit for CVE-2022-26318, a remote code execution vulnerability in WatchGuard XTM and FireWare OS, delivering a reverse shell via…

PoC exploit for CVE-2021-45105 (Log4j2 DOS) with Spring Boot web app, demonstrating infinite loop via crafted HTTP header/body payloads.

Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对…

Proof-of-concept exploit for Spring4Shell (CVE-2022-22965) that deploys a JSP webshell via crafted HTTP requests to vulnerable Spring Boot…

Python-based exploit script for Oracle WebLogic CVE-2020-14882 unauthorized bypass RCE. Tests authentication bypass and remote code execution via…

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

Exploit for Apache Tomcat CGI Servlet command injection (CVE-2019-0232) enabling remote code execution via crafted HTTP requests on affected versions.

Proof-of-concept exploit for CVE-2023-45158, a command injection vulnerability in web2py. Demonstrates remote code execution via crafted HTTP…