
CVE-2024-46986
Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

Authenticated RCE exploit for MotionEye <= 0.43.1b4 via client-side validation bypass on the image_file_name field. Includes reverse shell payload…

Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment…

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Authenticated remote code execution exploit for m1k1o's Blog v1.3 via unvalidated file upload, with webshell deployment and reverse shell…

Python exploit for CVE-2021-22205, a remote command execution in GitLab CE/EE via image file parsing. Supports vulnerability checking, batch…

Exploit script for CVE-2021-22204, an ExifTool RCE via malicious DjVu files, with manual exploitation steps and reverse shell payloads.

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Automated exploit for CVE-2024-25641 targeting Cacti 1.2.26. Achieves remote code execution via authenticated arbitrary file write in the Package…

Python exploit script for Elastix 2.2.0 LFI vulnerability (CVE-2012-4869) enabling remote code execution via Perl reverse shell payload injection.

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

Proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin, enabling web shell deployment for penetration…

Proof-of-concept exploit for CVE-2024-7627, an unauthenticated remote code execution vulnerability in Bit File Manager WordPress plugin. Automates…

Exploit for CVE-2024-5084: unauthenticated arbitrary file upload in Hash Form WordPress plugin, enabling remote code execution via Python script with…

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

Exploit for CVE-2022-26134 targeting Confluence Server with remote command execution and reverse shell capabilities. Supports batch scanning and…

Go-based exploit for CVE-2024-56348 targeting JetBrains TeamCity authentication bypass and remote code execution. Provides interactive shell, reverse…