
CVE-2021-40906
Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…

Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…

Web-Security-Learning

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of…

Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

A native backdoor module for Microsoft IIS (Internet Information Services)


Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

Escaner de identificacion de vulnerabilidades para CVE-2025-4322

Web Backdoor Cookie Script-Kit


LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Web application backdoor builder