
nmap-CVE-2022-21907
Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution.…

Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution.…

Proof-of-concept exploit for a Remote Code Execution vulnerability in RealPlayer G2 ActiveX control, leveraging javascript: and mhtml: URIs to…

A native backdoor module for Microsoft IIS (Internet Information Services)

In progress persistent download/upload/execution tool using Windows BITS.

Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

Technical documentation and proof-of-concept for CVE-2025-66837, a remote authenticated file upload vulnerability in ARIS allowing arbitrary code…

Zeek package that detects CVE-2022-22954 exploit attempts, logs exploit URIs and attacker response data to aid in incident response and network…

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

Authentication Bypass Vulnerability — CVE-2024–4358 — Telerik Report Server 2024

Documentation of CVE-2025-66838: a rate-limiting vulnerability in ARIS file upload API allowing authenticated remote attackers to cause denial of…

IIS 6.0 remote code execution exploit for CVE-2017-7269, supporting custom command payloads up to 8 bytes via WebDAV PROPFIND method.

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to…

Penetration testing assessment of a vulnerable IIS 6.0 WebDAV server, demonstrating reconnaissance, enumeration, exploitation (CVE-2017-7269), and…

Rust-based routing protocol suite implementing BGP, OSPF, IS-IS, RIP, and VRRP with YANG-modeled configuration, gNMI/gRPC automation, and built-in…

Fast IIS short filename enumeration tool that identifies hidden files and directories via tilde vulnerability, with automatic full filename…

Python proof-of-concept for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution on Windows Server 2003 R2.

Exploit for CVE-2017-7269: buffer overflow in IIS 6.0 WebDAV service enabling remote code execution via crafted PROPFIND request.