
Prestashop-CVE-2024-34716
Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

Python-based exploit for CVE-2018-1273 (Spring Data Commons RCE) with interactive command shell and HTTP POST payload injection for penetration…

Proof-of-concept exploit for CVE-2022-21587 targeting Oracle E-Business Suite with file overwrite and shell creation capabilities.

Automated exploit for CVE-2023-50643 targeting Evernote macOS via RunAsNode and enableNodeClilnspectArguments to achieve remote code execution and…

Python exploit for CVE-2025-32433 targeting Erlang OTP SSH server. Sends crafted SSH packets to open a reverse shell and gain root access.

Authenticated remote code execution exploit for OpenSTAManager via unvalidated ZIP upload, providing reverse shell and interactive webshell…

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

Proof-of-concept exploit for authenticated remote code execution in Krayin CRM v2.2.x via unrestricted file upload, supporting web shell and reverse…

Exploits CVE-2012-2982 in Webmin with a Rust PoC that delivers a configurable TCP reverse shell and optional Netcat listener.