
CVE-2020-14882
This script allows for remote code execution (RCE) on Oracle WebLogic Server

This script allows for remote code execution (RCE) on Oracle WebLogic Server

Exploit script for CVE-2025-50946

Remote shell on CVE-2009-4623

Script to automate PUT HTTP method exploitation to get shell

Windows privilege-escalation exploit abusing SeImpersonate via DiagTrack RPC, using Secondary Logon to get an INTERACTIVE token and gain SYSTEM.

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Exploiting a Cross-site request forgery (CSRF) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Repo that the MS15-011 exploit clones to get required files. Avoids having to download all files from exploit_dev.

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injection through the Webmin's File Manager feature

This is just a quick note on how to exploit these vulnerabilities to get root.

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

Exploiting a Cross-site request forgery (CSRF) attack to get a Command Injetion through the Webmin's Upload and Download feature

Apache Solr 1.4 Injection to get a shell

An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Command Injection through the Webmin's File Manager feature