
CVE-2006-20001
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

Python exploit script for CVE-2021-41773, a path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49, enabling automated…

Node.js proof-of-concept exploit for CVE-2016-4971, demonstrating wget FTP redirect filename trust vulnerability with a simple HTTP server.

Python-based simulated firewall to detect and block Spring4Shell (CVE-2022-22965) exploit attempts. This project filters HTTP requests by identifying…

Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

Proof-of-concept exploit for CVE-2025-27152 in Axios, demonstrating a server-side request forgery vulnerability in the popular HTTP client library.

Documented CVE-2021-41773 (Apache HTTP Server path traversal, CVSS 9.8) — produced CVSS breakdown, impact assessment, and a mitigation plan (patch to…

PoC of Backend HTTP Socket Poisoning, via HTTP Smuggling, presented in CVE-2019-15605

Exploit tool for CVE-2018-9995 that extracts credentials from exposed DVR devices via HTTP request with cookie bypass, targeting multiple vendor…

Detects the Heartbleed vulnerability (CVE-2014-0160) in OpenSSL on HTTP and HTTPS services via version checking, with guidance for using nmap,…

Test tool for CVE-2024-26144 that checks if web servers and CDNs improperly cache HTTP responses containing Set-Cookie headers, revealing cache…

Proof-of-concept demonstrating CVE-2022-0155 cookie theft via HTTP redirect in follow-redirects npm package, including Express server and client…

Proof-of-concept for CVE-2021-40346, demonstrating HTTP request smuggling in HAProxy via integer overflow, with Docker-based environment to bypass…

Proof-of-concept exploit for CVE-2022-21907, a remote code execution vulnerability in Windows HTTP Protocol Stack (HTTP.sys). Demonstrates…

Exploit for Jetty CVE-2020-27223, a vulnerability allowing remote code execution via crafted HTTP requests. Useful for penetration testing and…

Exploit for CVE-2014-6271 (Shellshock) enabling remote code execution via crafted HTTP headers against vulnerable Bash versions.

CVE-2019-10092: Limited Cross-Site Scripting via "Proxy Error" Page in Apache HTTP Server