
CVE-2012-2593
Atmail XSS-CSRF-RCE Exploit Chain

Atmail XSS-CSRF-RCE Exploit Chain


Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Payload Generation Framework

Self contained htaccess shells and attacks

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)

Nano is a family of PHP web shells which are code golfed for stealth.


complex webshell manager, quasi-http botnet.

CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.

A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.


C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

RCE exploit for CVE-2023-3519
