
CVE-2021-21425-RCE
Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

Exploit for ProFTPD 1.3.5 CVE-2015-3306 that writes a PHP backdoor to the target webroot and spawns a reverse shell for remote code execution.

Automates a CSRF attack against CVE-2024-34716 to deploy a PHP reverse shell on PrestaShop, with automated payload packaging and Netcat listener…

GUI-based exploit tool for CVE-2020-14882 targeting Oracle WebLogic servers. Supports reverse shell payload generation, proxy configuration, and…

XWiki Unauthenticated RCE Exploit for Reverse Shell

Exploit for CVE-2009-2265 targeting ColdFusion 8.0.1 with JSP reverse shell payload generation and automated upload.

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Proof-of-concept exploit for CVE-2021-41773, a path traversal and remote code execution vulnerability in Apache HTTP Server 2.4.49. Automates…

Reverse shell for CVE-2024-28397.

Python exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805) enabling remote command execution and reverse shell on vulnerable…

Exploit for CVE-2009-4623: remote file inclusion in Advanced Comment System 1.0 enabling arbitrary PHP code execution and reverse shell via ACS_path…

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Exploit for CVE-2024-39205, a js2py sandbox escape that enables remote code execution and establishes a reverse shell.

Python exploit script for CVE-2024-28397 targeting js2py <= v0.74. Supports reverse shell and custom command execution via HTTP endpoint.

Python exploit for CVE-2015-3306 targeting ProFTPD servers. Automates PHP reverse shell upload via FTP to achieve remote code execution on vulnerable…

IBM i DDM Unauthenticated RCE - Java Reverse Shell

This script exploits CVE-2025-62369 in Xibo CMS to execute a reverse shell command.