
CVE-2023-422-Chamilo-LMS-RCE
Remote Code Execution for Chamilo LMS

Remote Code Execution for Chamilo LMS


winrar exploit 6.22 <=

CVE-2021-44228

Go-based exploit for CVE-2025-32433

CVE-2021-46363: Formula Injection in Magnolia CMS

Created this exploit for the Hack The Box machine, Blurry.

orangescrum 1.8.0 - Remote Command Execution RCE (unauthenticated)

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

Proof of concept for CVE-2020-11819 and CVE-2020-15946

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_file Task

Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

A script to exploit CVE-2020-1472 (Zerologon)

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection