
webshell
This is a webshell open source project

This is a webshell open source project

Tools that trigger False Positive AV alerts

Proof-of-concept exploit for CVE-2024-48990 demonstrating PYTHONPATH hijacking in needrestart to achieve local privilege escalation via SUID binary…

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

Data-only local privilege escalation exploit for Linux kernel io_uring CVE-2024-0582, using sprayed file structures and ext4_file_operations hooks to…

CVE-2024-35250 的 Beacon Object File (BOF) 实现。

Tools and code for generating a malicious JAR to exploit jvmtiAgentLoad

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

My take on the needrestart Python CVE-2024-48990

CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件

Exploit for CVE-2024-10793: stored XSS in WP Activity Log plugin. Includes a detection script and a shell-based exploit for unauthenticated attackers.

For when DLLMain is the only way

CVE-2024-40431+CVE-2022-25479 chain for EOP(DATA ONLY ATTACK)

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

PrusaSlicer Arbitrary Code Execution using .3mf

C# / .NET version of CVE-2023-21768

Threadless Process Injection using remote function hooking.

Python-based exploit and reverse shell payload generator for CVE-2023-42115, featuring scan and exploit modes with cross-platform payload creation.