
CVE-2021-2394
Proof-of-concept exploit for CVE-2021-2394, a remote code execution vulnerability in Oracle WebLogic Server. Uses LDAP or RMI deserialization to…

Proof-of-concept exploit for CVE-2021-2394, a remote code execution vulnerability in Oracle WebLogic Server. Uses LDAP or RMI deserialization to…

CVE-2021-44228 (Log4Shell) Proof of Concept

Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Docker-based reproduction environment for CVE-2021-44228 (Log4Shell) with marshalsec LDAP server, exploit web server, and vulnerable Java application…

Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

Java-based exploit for CVE-2023-21839 targeting Oracle WebLogic Server versions 12.2.1.3.0 and 12.2.1.4.0 via LDAP injection for remote code…

A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell

Python proof-of-concept exploit for CVE-2023-21839 targeting WebLogic servers via LDAP injection for unauthenticated remote code execution.

Java-based exploit for CVE-2024-21006, delivering a payload via LDAP to a target IP and port. Includes compiled JAR and source for customization.

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

Docker-based RCE exploit demo for Log4Shell (CVE-2021-44228) with vulnerable Spring Boot app, malicious LDAP server, and payload delivery via JNDI…

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection, LDAP reference server, and WAF bypass techniques for testing Log4j RCE…