Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
☆95Oct 18, 2022Updated 3 years ago
Alternatives and similar repositories for ColdFusionPwn
Users that are interested in ColdFusionPwn are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- weblogic t3 deserialization rce☆266Jul 13, 2017Updated 9 years ago
- Java Message Exploitation Tool☆507Jul 6, 2022Updated 4 years ago
- fastjson 1.2.68 版本 autotype bypass☆141Aug 9, 2026Updated 3 weeks ago
- PoC code for crashing windows active directory☆34Sep 19, 2018Updated 7 years ago
- CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit☆25Sep 4, 2018Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Mogwai Java Management Extensions (JMX) Exploitation Toolkit☆174Jul 21, 2016Updated 10 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Nov 30, 2018Updated 7 years ago
- CVE-2018-8021 Proof-Of-Concept and Exploit☆104Dec 3, 2018Updated 7 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆121Jan 9, 2018Updated 8 years ago
- Java RMI enumeration and attack tool.☆747Sep 28, 2017Updated 8 years ago
- XXE injection (file disclosure) exploit for Apache OFBiz < 16.11.04☆12Oct 16, 2018Updated 7 years ago
- CVE-2018-6574 POC : golang 'go get' remote command execution during source code build☆24Jan 14, 2022Updated 4 years ago
- Proof of concept showing how to exploit the CVE-2018-11759☆39Dec 11, 2018Updated 7 years ago
- A Java serializer in JavaScript☆80May 21, 2018Updated 8 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM☆51Mar 14, 2018Updated 8 years ago
- SerialWriter is an incomplete implementation of Java serialization for study of Java deserialization vulnerabilities.☆104Feb 28, 2018Updated 8 years ago
- Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch☆114May 21, 2018Updated 8 years ago
- A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)☆37Sep 8, 2017Updated 8 years ago
- 常用系统服务默认端口列表☆13Apr 25, 2017Updated 9 years ago
- .NET Deserialization Passive Scanner☆46Mar 23, 2018Updated 8 years ago
- ☆17Oct 25, 2018Updated 7 years ago
- A fake JDBC driver that allows OS command execution.☆125Oct 2, 2022Updated 3 years ago
- CVE-2018-3245-PoC☆172Jul 13, 2021Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Zimbra邮件系统漏洞 XXE/RCE/SSRF/Upload GetShell Exploit 1. (CVE-2019-9621 Zimbra<8.8.11 XXE GetShell Exploit)☆79Feb 22, 2023Updated 3 years ago
- 可能有一些你没见过的端口扫描脚本☆11Nov 28, 2018Updated 7 years ago
- JNDI Attacking Tool☆244Jul 11, 2022Updated 4 years ago
- Some payloads of JNDI Injection in JDK 1.8.0_191+☆485Dec 9, 2020Updated 5 years ago
- PoC Code for CVE-2018-16712 (exploit by MmMapIoSpace)☆24Dec 1, 2018Updated 7 years ago
- 改造一个基于jrmp的AMF反序列化利用工具☆16Jul 7, 2022Updated 4 years ago
- 适用于weblogic和Tomcat的无文件的内存马(memshell)☆272Mar 4, 2022Updated 4 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆102Mar 10, 2020Updated 6 years ago
- ☆41Nov 9, 2018Updated 7 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- CVE-2018-3191 反弹shell☆15Oct 23, 2018Updated 7 years ago
- Apache Solr Exploits 🌟☆345Oct 13, 2020Updated 5 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆620Mar 4, 2021Updated 5 years ago
- Some scripts and exploits☆147Jul 9, 2018Updated 8 years ago
- CVE-2019-2725 命令回显☆433May 8, 2023Updated 3 years ago
- Web directory and file discovery.☆18Oct 31, 2022Updated 3 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.优化了一些东西。☆212Jan 17, 2022Updated 4 years ago