
php-8.1.0-dev-backdoor-rce
PHP 8.1.0-dev Backdoor System Shell Script

PHP 8.1.0-dev Backdoor System Shell Script

Exploit for ProFTPD 1.3.5 CVE-2015-3306 that writes a PHP backdoor to the target webroot and spawns a reverse shell for remote code execution.

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Yet Another PHP Shell - The most complete PHP reverse shell

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

Generates Windows reverse shell backdoors with automatic IP poisoning, leveraging Metasploit for payload creation and Apache for delivery in…

Meterpreter auto exploit program

Master's thesis research on CVE-2021-4034 (PwnKit) local privilege escalation. Multi-payload Python exploit with 7 modes including interactive shell,…

WonderCMS Plugin

UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Python exploit for VSFTP 2.3.4 backdoor (CVE-2011-2523) that triggers the backdoor and provides shell access on port 6200.

TinySHell port to SCTP

Manual and automated exploitation walkthrough for vsftpd 2.3.4 backdoor (CVE-2011-2523) with custom reverse shell payload and Metasploit integration…

Python exploit for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) delivering a reverse shell via Netcat listener.

Shell scripts to detect CVE-2024-3094 backdoor in liblzma5 across Kubernetes pods and Docker containers, with SBOM generation via Trivy for…

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.