
cve-2019-3396
Ruby exploit for CVE-2019-3396 enabling unauthenticated Confluence remote code execution, including target scanning and command execution via an FTP…

Ruby exploit for CVE-2019-3396 enabling unauthenticated Confluence remote code execution, including target scanning and command execution via an FTP…

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…

Python PoC exploit for CVE-2015-3306 ProFTPD directory traversal. Copies files and drops a PHP backdoor into webroot for remote command execution via…

Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)

ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container

Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)

Python exploit for CVE-2025-47812, achieving remote code execution on Wing FTP Server via Lua injection in the login username parameter. Supports…

Exploit and scanner for CVE-2025-47812 targeting Wing FTP Server unauthenticated remote code execution, supporting single-target, mass scanning,…

PHP Webshell with handy features

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

Wing FTP Server RCE via Lua Injection

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

Proof-of-concept exploit for CVE-2025-47812: unauthenticated remote code execution in Wing FTP Server <= 7.4.3 via NULL byte injection in the…

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

Docker test environment for CVE-2025-34299 - Monsta FTP Pre-Auth RCE vulnerability