


Server-Side Template Injection Exploit

Apache ActiveMQ Remote Code Execution Exploit

Remote Code Execution at Rittal

An interactive multi-user web JS shell


Single-file PHP shell

Directory transversal to remote code execution

Python 2.7


PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

Authenticated Remote Command Execution - Webmin <= 1.910

A webshell framework for penetration testers.

Empire client application

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Easy peasy file uploads

All Working Exploits