
CVE-2011-2523
From-scratch exploit development in Python. No Metasploit. No frameworks. Raw socket-level implementation of real CVEs against authorized lab targets.

From-scratch exploit development in Python. No Metasploit. No frameworks. Raw socket-level implementation of real CVEs against authorized lab targets.

CVE-2025-47812 Poc for wingdata HTB

CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit

POCs to demonstrate CVE-2026-42167 in ProFTPD

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

RCE for WingFTP v4.7.3

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.

Proof-of-concept exploit for CVE-2025-47812: unauthenticated remote code execution in Wing FTP Server <= 7.4.3 via NULL byte injection in the…

CVE-2025-47812 POC

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

CVE-2025-47812: Wing FTP Server 7.4.3 UnauthN RCE in sh

Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability

Detection for CVE-2025-34299

Python PoC exploit for CVE-2015-3306 ProFTPD directory traversal. Copies files and drops a PHP backdoor into webroot for remote command execution via…

Python exploit for CVE-2025-47812, achieving remote code execution on Wing FTP Server via Lua injection in the login username parameter. Supports…

CVE-2025-47812

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…