Exploit-Framework

April 8, 2019 · View on GitHub

Backers on Open Collective Sponsors on Open Collective

Exploits:

VendorVulnerabilityEffected VersionDescriptionAuthor
zblogNOT_CVE<=1.5.1Zblog Authenticated LFI@Shutdown_r
OpenSNSNOT_CVE<=3.31OpenSNS UnAuthenticated GetShell@90sec
JoomlaCVE-2015-85621.5<3.45Joomla Header Unauthenticated RCE@Andrew McNicol
CodiadCVE-2017-11366<=2.8.3Codiad Authenticated RCE@WangYihang
CodiadCVE-2014-9581<=2.4.3Codiad Authenticated LFI@TaurusOmar
SeaCMSCVE-2017-17561<=6.56SeaCMS Authenticated GetShell@WangYihang
SeaCMSNOT_CVE<=6.28SeaCMS UnAuthenticated RCE@没穿底裤
phpMoAdminCVE-2015-2208<=1.1.2phpMoAdmin UnAuthenticated RCEUnknown
WordPressCVE-2017-5487<4.7.1WordPress Username Enumeration@Dctor
DedeCMSNOT_CVE<=5.6DedeCms recommend.php SQL injection@没穿底裤
KernelCVE-2016-51952.6.22<3.9DirtyC0w Privilege Escalation@nowsecure

Video:

asciicast

WIKI:

https://github.com/WangYihang/Exploit-Framework/wiki

Contribution:

1. Guidance of writing exploit module

TODO:

  • 解析字符串
  • 深层模块化
  • 上下文栈维护
  • 日志
  • 自动补全
  • Exploit 搜索
  • Wiki
  • Exploit 规范
  • 维护 Reverse Shell (结合 Reverse-Shell-Manager)
  • Payload 模块
  • 免杀模块
  • 维护一句话木马 (结合 Webshell-Sniper)
  • 数据库
  • Web 前端

Contributors

This project exists thanks to all the people who contribute.

Backers

Thank you to all our backers! 🙏 [Become a backer]

Sponsors

Support this project by becoming a sponsor. Your logo will show up here with a link to your website. [Become a sponsor]