
php-reverse-shell
PHP shells that work on Linux OS, macOS, and Windows OS.

PHP shells that work on Linux OS, macOS, and Windows OS.

Proof-of-concept exploit for CVE-2025-24801, an LFI-to-RCE vulnerability in GLPI 10.0.17. Automates login, enables PHP uploads, and uploads a reverse…

Python exploit for CVE-2023-45878 targeting Gibbon LMS 25.0.1. Uses arbitrary file write to upload a PHP web shell and execute a PowerShell reverse…

PHP reverse shell script for establishing a remote TCP connection, enabling command execution on a target web server.

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

PHP 8.1.0-dev Backdoor System Shell Script

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

Exploit for CVE-2020-24186 in WordPress wpDiscuz 7.0.4 that uploads a reverse PHP shell for remote code execution.


Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

Proof-of-concept exploit for CVE-2025-9074 enabling Docker Desktop API escape via raw HTTP requests. Provides an emulated interactive shell inside a…

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing race condition to create a sudo user and gain root shell on…

Python proof-of-concept for remote code execution in Grafana via SQL Expressions, exploiting insufficient input sanitization to execute arbitrary…

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

One-shot exploit for Gogs symlink RCE (CVE-2025-8110) that triggers a reverse shell via a single PUT request to UpdateRepoFile.