
zaphoster
Fix host header error in zaproxy

Fix host header error in zaproxy

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

JSON Web Token Hack Toolkit

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Demonstrates CVE-2026-11108 integer overflow in kmalloc simulation, causing heap overflow and potential arbitrary code execution from crafted…

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header.

Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Python proof-of-concept exploit for Apache Struts2 RCE vulnerability CVE-2017-5638, demonstrating remote code execution via crafted Content-Type…

Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2017-5638, demonstrating exploitation via crafted Content-Type…