
YAPS
Yet Another PHP Shell - The most complete PHP reverse shell

Yet Another PHP Shell - The most complete PHP reverse shell

Proof-of-concept exploit for CVE-2022-22963, a Spring Cloud Function SpEL injection leading to remote code execution. Includes a shell script for…

PostShell - Post Exploitation Bind/Backconnect Shell

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Testing CVE-2022-22968

This script exploits CVE-2025-62369 in Xibo CMS to execute a reverse shell command.

Python proof-of-concept for authenticated remote code execution in PandoraFMS 7.0-NG 742, enabling admin users to upload malicious PHP and obtain a…

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

Salsa Tools - ShellReverse TCP/UDP/ICMP/DNS/SSL/BINDTCP/Shellcode/SILENTTRINITY and AV bypass, AMSI patched

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

Standalone proof-of-concept exploit for CVE-2023-37903 that triggers the targeted vulnerability and establishes a reverse shell.

Exploit for CVE-2024-39205, a js2py sandbox escape that enables remote code execution and establishes a reverse shell.

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

Proof of concept for CVE-2022-31814

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

Hide your Powershell script in plain sight. Bypass all Powershell security features

Reverse shell for CVE-2024-28397.

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…