
p0wny-shell
Single-file PHP shell

Single-file PHP shell

Authenticated Remote Command Execution - Webmin <= 1.910


All Working Exploits

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

Directory transversal to remote code execution


Apache ActiveMQ Remote Code Execution Exploit

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)


Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object.…

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

A PoC Java Stager which can download, compile, and execute a Java file in memory.