
KindaRails2Shell
Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Exploit for Rails CVE-2019-5420 targeting insecure session key derivation in development mode, enabling remote code execution via crafted requests.

Dockerized exploit environment for CVE-2019-5420 (Ruby on Rails Active Storage) enabling remote code execution. Designed for educational testing and…

Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

Proof-of-concept exploit for CVE-2019-5420 (Rails cookie deserialization) with argparse-based cookie modification, designed for PentesterLab practice.

Proof-of-concept exploit for CVE-2019-5420, a remote code execution vulnerability in Ruby on Rails, designed for educational purposes.

Test cases for broken MIME and tools to generate and process these

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

Proof-of-concept exploit for CVE-2014-0130, a Rails directory traversal vulnerability. Demonstrates path traversal payload and references HackerOne…

Python exploit for CVE-2020-8165 targeting Rails MemCacheStore and RedisCacheStore. Enables remote command execution via user-provided object…

Automated exploit script for CVE-2020-8165 targeting Rails applications, enabling remote code execution via crafted payloads.

Proof-of-concept exploit for CVE-2019-5420 targeting Rails development mode secret token disclosure to escalate privileges via cookie manipulation.

Step-by-step exploit for Ruby on Rails CVE-2019-5420 RCE via insecure Marshal deserialization, with payload generation and reverse shell capture.

Proof-of-concept exploit for CVE-2016-0752, a Rails dynamic render remote code execution vulnerability, with setup instructions and reference to a…

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156

Go-based scanner for CVE-2019-5418 (Ruby on Rails file disclosure) that reads a list of websites and tests for the vulnerability using a burl-derived…