
Prestashop-CVE-2024-34716
Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

complex webshell manager, quasi-http botnet.

ImaegMagick Code Execution (CVE-2016-3714)

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Royal Elementor Addons - Unauthenticated Remote Code Execution

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

Customized this for my own use

Explicação + Lab no THM