
hiphp
PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)

Proof-of-concept demonstrating Local File Inclusion and Server-Side Request Forgery in PDFocus, with steps to reproduce and demo screenshots.

Arbitrary File Read and DoS in vendure-ecommerce exploit

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Working PoCs for three NextGen Connect 4.5.2 vulnerabilities.

Local file inclusion exploitation tool

Atlassian Jira unauthen template injection

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Proof-of-concept exploit for CVE-2022-44268, an arbitrary file read vulnerability in ImageMagick, enabling local file disclosure via crafted PNG…

A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.

Python exploit script for CVE-2023-46604 (Apache ActiveMQ deserialization RCE) with a PoC XML payload. Automates exploitation via crafted OpenWire…

PoC for CVE-2026-66066 in Ruby on Rails

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…