HTTP/HTTPS:
Exploitation
RCE, SQLi, XSS, LFI, SSRF, XXE, JWT, file upload and more
CVE-2025-54068 Livewire RCE Exploitation
Exploits CVE-2025-54068, a critical Livewire RCE vulnerability via malicious component payloads over HTTP/HTTPS to achieve remote code execution.
File Inclusion Exploitation
Exploit Local and Remote File Inclusion vulnerabilities in web apps to read sensitive files, achieve RCE, and bypass filters via path traversal and log poisoning.
Git Repository Exploitation
Exploit exposed .git directories to reconstruct source code, extract credentials, and uncover sensitive application logic from misconfigured web servers.
Laravel Ignition Remote Code Execution - CVE-2021-3129
Exploiting CVE-2021-3129 in Laravel Ignition to achieve RCE via malicious log file deserialization through the debug mode endpoint.
SSTI Exploitation
Exploit Server-Side Template Injection vulnerabilities to achieve RCE by identifying template engines, crafting payloads, and escaping sandbox restrictions.
WordPress Exploitation
Covers exploiting WordPress vulnerabilities including plugin/theme CVEs, xmlrpc abuse, credential attacks, and achieving RCE via malicious plugin uploads.