
Prestashop-CVE-2024-34716
Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Reverse Shell CVE for iDRAC 7 & 8 with firmware 2.52.52.52 and below.

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

Cross-platform interactive shell for Microsoft Defender for Endpoint Live Response

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

Multi-hop proxy tool for pentesters enabling traffic routing through multiple nodes, SOCKS5/SSH tunneling, port forwarding, remote shell, and…

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully…

RSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation…

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

A free and open source command-line shell and scripting language designed especially for security testing

Python-based exploit for CVE-2018-1273 (Spring Data Commons RCE) with interactive command shell and HTTP POST payload injection for penetration…

Proof-of-concept exploit for CVE-2026-4480, an unauthenticated remote command execution in Samba's print subsystem via %J injection. Includes reverse…

Proof-of-concept exploit for CVE-2022-21587 targeting Oracle E-Business Suite with file overwrite and shell creation capabilities.