
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

Demo project how to bypass the disable_functions security control of PHP on Linux

Proof-of-concept exploit for CVE-2024-2961, leveraging iconv encoding flaws and PHP filter chains to read arbitrary files from vulnerable servers via…

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell…

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar

PoC of how to exploit a RCE vulnerability of the example DAGs in Apache Airflow <1.10.11

Python PoC script exploiting an arbitrary file upload vulnerability in Best House Rental Management System 1.0 to upload a PHP web shell and execute…

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

Tips on how to write exploit scripts (faster!)

Tests your WAF with +160 payloads

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…