
gimmeSH
For pentesters who don't wanna leave their terminals.

For pentesters who don't wanna leave their terminals.

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

[CVE-2024-26581] Vulnerability Checker for BGN Internal

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

Demonstration exploit for CVE-2019-18276, a local privilege escalation vulnerability in Bash, using a crafted shared library to gain root access.

A bash scanner for detecting CVE-2025-55182 vulnerability in Next.js applications. And a PoC nodejs script

A Bash implementation of copyfail (CVE-2026-31431)

Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor

Provides a bash workaround script to mitigate CVE-2026-31431, preventing remote code execution via copy.fail exploit. Includes usage instructions for…

Patched GNU Bash 4.3 with fix for Shellshock (CVE-2014-6271). Provides a secure Bourne Again SHell with command-line editing, job control, and…

Patched GNU Bash 3.2 with a fix for CVE-2014-6271 (Shellshock). Provides a standard POSIX shell with command-line editing, job control, and history…

Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying

Reverse Shell Detection with Machine Learning

Script to exploit CVE-2023-38035

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…