
CVE-2021-22880
Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Proof-of-concept exploit for CVE-2018-3760, a path traversal vulnerability in Ruby on Rails. Demonstrates the flaw for testing and educational…

Docker-based lab environment for CVE-2019-5418 Ruby on Rails path traversal exploit, with PoC curl commands to read arbitrary server files via…

Python exploit shell for CVE-2020-8165, providing a reverse shell payload for remote code execution on vulnerable Rails applications.

Bash-based proof-of-concept exploit for CVE-2016-2098, targeting Ruby on Rails Action Pack remote code execution via unrestricted render method.

Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

Proof-of-concept exploit for CVE-2020-8165, a Ruby on Rails remote code execution vulnerability. Demonstrates exploitation of the unsafe…

Node.js exploit for CVE-2015-3224, achieving unauthenticated RCE on Rails web-console by spoofing X-Forwarded-For to bypass IP whitelist and…

Demonstrates exploitation of Ruby on Rails CVE-2019-5418, a file disclosure vulnerability, for educational purposes.

Python exploit script for CVE-2013-0156, a remote code execution vulnerability in Ruby on Rails via insecure YAML deserialization. Designed for…

Interactive OAuth phishing toolkit for Office365 that performs token theft, email search/sending, file exfiltration, and document replacement via…

Pseudo shell for exploiting CVE-2013-0156, providing a command-line interface for automated exploitation of the Ruby on Rails XML/YAML parser…

Executes remote code on vulnerable Rails applications via YAML deserialization (CVE-2013-0156); designed for CTFs and authorized penetration tests.

Python exploit for CVE-2015-3224, bypassing IP whitelist in Ruby on Rails web console to achieve remote code execution with interactive reverse shell.

Proof-of-concept exploit for CVE-2019-5418, demonstrating file content disclosure on Ruby on Rails via crafted Accept headers, with a demo…

Proof-of-concept exploit for CVE-2012-2661, an SQL injection vulnerability in Ruby on Rails ActiveRecord. Includes a write-up in Malay demonstrating…

Docker-based lab environment and exploit script for CVE-2020-8163, a blind remote code execution vulnerability in Rails versions before 5.0.1 and…

Proof-of-concept exploit for CVE-2019-5420, demonstrating remote code execution in Ruby on Rails via ActiveSupport deserialization. Generates signed…