
p0wny-shell
Single-file PHP shell

Single-file PHP shell

Authenticated Remote Command Execution - Webmin <= 1.910

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781). Executes arbitrary commands on vulnerable…

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

Pre-auth RCE exploit for Mobile Mouse 3.6.0.4 via TCP (port 9099) and WebSocket (port 35913) with Python scripts for unauthenticated command…

CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

Directory transversal to remote code execution

Apache ActiveMQ Remote Code Execution Exploit

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781) that executes arbitrary commands on vulnerable…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object.…

Exploit implementation for CVE-2014-6287, targeting a remote code execution vulnerability in a web application. Provides a proof-of-concept for…

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

A PoC Java Stager which can download, compile, and execute a Java file in memory.