
tomcat-cluster-session-sync-exp
tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞…

tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞…

his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in…

Exploit for CVE-2017-7269 targeting Microsoft IIS 6.0 WebDAV remote code execution vulnerability. Enables authenticated buffer overflow attacks on…

Exploit for CVE-2023-46747, a remote code execution vulnerability in F5 BIG-IP, allowing unauthorized user creation and command execution.

Improved DOS exploit for wordpress websites (CVE-2018-6389)

(PoC) Python version of CVE-2019-11043 exploit by neex

Exploit for the vulnerability CVE-2024-43044 in Jenkins

Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE

Proof-of-concept exploit for CVE-2019-0604, a remote code execution vulnerability in Microsoft SharePoint. Provides a working implementation for…

Python exploit for CVE-2019-19781 targeting Citrix ADC with template injection to achieve remote code execution on vulnerable gateways.

Security training for the apps you actually ship. Open your browser and start hacking.

proxylogon exploit - CVE-2021-26857

A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.

Spring Cloud Gateway 远程代码执行漏洞Exp Spring_Cloud_Gateway_RCE_Exp-CVE-2022-22947

Time Based SQL Injection in Zabbix Server Audit Log --> RCE

cve-2019-0604 SharePoint RCE exploit

CVE-2021-22205 Unauthorized RCE

The whole collection of Exploits developed by me (Hacker5preme)