<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse-Shell — PoC Archive</title><link>https://poc.intelseclab.com/tags/reverse-shell/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/reverse-shell/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-57819-freepbx-sqli-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-57819-freepbx-sqli-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-57819. Status: Weaponized. Affects: Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module). Tags: freepbx, sangoma, sqli, unauthenticated, ajax-php, cron-jobs, reverse-shell, voip, asterisk, cwe-89.</description><category>web</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>sqli</category><category>unauthenticated</category><category>ajax-php</category><category>cron-jobs</category><category>reverse-shell</category><category>voip</category><category>asterisk</category><category>cwe-89</category></item><item><title>Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14700-crafty-controller-ssti-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14700-crafty-controller-ssti-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-14700. Status: Weaponized. Affects: Crafty Controller (Minecraft server management panel). Tags: crafty-controller, minecraft, jinja2, ssti, server-side-template-injection, reverse-shell, tornado, xsrf, python, cwe-1336.</description><category>web</category><category>Critical</category><category>crafty-controller</category><category>minecraft</category><category>jinja2</category><category>ssti</category><category>server-side-template-injection</category><category>reverse-shell</category><category>tornado</category><category>xsrf</category><category>python</category><category>cwe-1336</category></item><item><title>Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</guid><description>Critical severity — network · CVE-2026-33824. Status: Weaponized. Affects: Windows IKEv2 IPsec driver (ikeext.dll). Tags: ikev2, windows-kernel, double-free, ikeext, rop-chain, heap-grooming, reverse-shell, anti-debug, packet-fragmentation.</description><category>network</category><category>Critical</category><category>ikev2</category><category>windows-kernel</category><category>double-free</category><category>ikeext</category><category>rop-chain</category><category>heap-grooming</category><category>reverse-shell</category><category>anti-debug</category><category>packet-fragmentation</category></item><item><title>Samba spoolss Print Job Command Injection RCE (CVE-2026-4480)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-4480-samba-spoolss-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-4480-samba-spoolss-rce/</guid><description>Critical severity — network · CVE-2026-4480. Status: PoC. Affects: Samba (spoolss / print spooler RPC service). Tags: samba, spoolss, smb, printer, rpc, command-injection, reverse-shell.</description><category>network</category><category>Critical</category><category>samba</category><category>spoolss</category><category>smb</category><category>printer</category><category>rpc</category><category>command-injection</category><category>reverse-shell</category></item><item><title>MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</guid><description>Critical severity — binary · CVE-2026-1668. Status: Weaponized. Affects: MIPS-based managed switch firmware (web management HTTP server), e.g. SG2005P/SG2008/SG2016P/SG2210MP/SG2218/SG2428/SG3210/SL2428/TL-SG2428 series firmware built around 2025-10-31. Tags: mips, embedded-linux, kernel-exploit, firmware, managed-switch, reverse-shell, pre-auth, shellcode.</description><category>binary</category><category>Critical</category><category>mips</category><category>embedded-linux</category><category>kernel-exploit</category><category>firmware</category><category>managed-switch</category><category>reverse-shell</category><category>pre-auth</category><category>shellcode</category></item><item><title>MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27483-mindsdb-path-traversal-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27483-mindsdb-path-traversal-rce/</guid><description>Critical severity — web · CVE-2026-27483. Status: Weaponized. Affects: MindsDB (version observed: 25.9.1.0). Tags: mindsdb, path-traversal, rce, reverse-shell, unauthenticated, pip-overwrite, python.</description><category>web</category><category>Critical</category><category>mindsdb</category><category>path-traversal</category><category>rce</category><category>reverse-shell</category><category>unauthenticated</category><category>pip-overwrite</category><category>python</category></item><item><title>MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23744-mcpjam-inspector-htb-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23744-mcpjam-inspector-htb-rce/</guid><description>Critical severity — web · CVE-2026-23744. Status: PoC. Affects: MCPJam Inspector v1.4.2. Tags: mcpjam-inspector, mcp, command-injection, rce, curl, hack-the-box, reverse-shell, chained-privesc.</description><category>web</category><category>Critical</category><category>mcpjam-inspector</category><category>mcp</category><category>command-injection</category><category>rce</category><category>curl</category><category>hack-the-box</category><category>reverse-shell</category><category>chained-privesc</category></item><item><title>MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23520-mcpjam-inspector-vhost-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23520-mcpjam-inspector-vhost-rce/</guid><description>Critical severity — web · CVE-2026-23520. Status: PoC. Affects: Arcane v1.13.0 (MCPJam Inspector component). Tags: mcp, mcpjam-inspector, arcane, command-injection, rce, host-header, vhost-routing, reverse-shell.</description><category>web</category><category>Critical</category><category>mcp</category><category>mcpjam-inspector</category><category>arcane</category><category>command-injection</category><category>rce</category><category>host-header</category><category>vhost-routing</category><category>reverse-shell</category></item><item><title>Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40897-mathjs-sandbox-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40897-mathjs-sandbox-bypass-rce/</guid><description>Critical severity — web · CVE-2026-40897. Status: Weaponized. Affects: Math.js expression parser (Node.js library). Tags: mathjs, nodejs, sandbox-bypass, rce, expression-parser, prototype-pollution-adjacent, reverse-shell, javascript.</description><category>web</category><category>Critical</category><category>mathjs</category><category>nodejs</category><category>sandbox-bypass</category><category>rce</category><category>expression-parser</category><category>prototype-pollution-adjacent</category><category>reverse-shell</category><category>javascript</category></item><item><title>Langflow Custom Component Remote Code Execution — CVE-2026-33017</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33017-langflow-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33017-langflow-rce/</guid><description>Critical severity — web · CVE-2026-33017. Status: PoC. Affects: Langflow (flow-building / LLM pipeline platform). Tags: langflow, rce, custom-component, code-execution, flow-builder, reverse-shell, curl.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>custom-component</category><category>code-execution</category><category>flow-builder</category><category>reverse-shell</category><category>curl</category></item><item><title>Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38526-krayin-crm-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38526-krayin-crm-file-upload-rce/</guid><description>Critical severity — web · CVE-2026-38526. Status: Weaponized. Affects: Krayin CRM. Tags: krayin-crm, laravel, unrestricted-file-upload, tinymce, rce, reverse-shell, authenticated.</description><category>web</category><category>Critical</category><category>krayin-crm</category><category>laravel</category><category>unrestricted-file-upload</category><category>tinymce</category><category>rce</category><category>reverse-shell</category><category>authenticated</category></item><item><title>ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3102-exiftool-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3102-exiftool-command-injection/</guid><description>High severity — binary · CVE-2026-3102. Status: PoC. Affects: ExifTool. Tags: exiftool, command-injection, macos, metadata, reverse-shell, tagsfromfile, perl.</description><category>binary</category><category>High</category><category>exiftool</category><category>command-injection</category><category>macos</category><category>metadata</category><category>reverse-shell</category><category>tagsfromfile</category><category>perl</category></item><item><title>Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3300-everest-forms-code-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3300-everest-forms-code-injection/</guid><description>Critical severity — web · CVE-2026-3300. Status: Weaponized (includes working reverse-shell payload builder and listener). Affects: Everest Forms Pro (WordPress plugin) — Calculation Addon. Tags: wordpress, everest-forms-pro, php-code-injection, rce, reverse-shell, form-calculation, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>everest-forms-pro</category><category>php-code-injection</category><category>rce</category><category>reverse-shell</category><category>form-calculation</category><category>unauthenticated</category></item><item><title>Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</guid><description>Critical severity — web · CVE-2026-23500 / GHSA-w5j3-8fcr-h87w. Status: PoC. Affects: Dolibarr ERP/CRM. Tags: dolibarr, os-command-injection, rce, authenticated, php, odt-to-pdf, reverse-shell, erp.</description><category>web</category><category>Critical</category><category>dolibarr</category><category>os-command-injection</category><category>rce</category><category>authenticated</category><category>php</category><category>odt-to-pdf</category><category>reverse-shell</category><category>erp</category></item><item><title>Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31816-budibase-auth-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31816-budibase-auth-bypass-rce/</guid><description>Critical severity — web · CVE-2026-31816. Status: Weaponized. Affects: Budibase (low-code platform). Tags: budibase, auth-bypass, rce, plugin-upload, reverse-shell, low-code, python, datasource-plugin.</description><category>web</category><category>Critical</category><category>budibase</category><category>auth-bypass</category><category>rce</category><category>plugin-upload</category><category>reverse-shell</category><category>low-code</category><category>python</category><category>datasource-plugin</category></item><item><title>IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE</title><link>https://poc.intelseclab.com/pocs/cloud/2026-05-17_ingressnightmare-k8s-ingress-nginx-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-05-17_ingressnightmare-k8s-ingress-nginx-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514. Status: Weaponized. Affects: Kubernetes Ingress-NGINX Controller (ingress-nginx). Tags: RCE, Kubernetes, ingress-nginx, admission-controller, unauthenticated, nginx-config-injection, cluster-takeover, k8s, shared-object, reverse-shell.</description><category>cloud</category><category>Critical</category><category>RCE</category><category>Kubernetes</category><category>ingress-nginx</category><category>admission-controller</category><category>unauthenticated</category><category>nginx-config-injection</category><category>cluster-takeover</category><category>k8s</category><category>shared-object</category><category>reverse-shell</category></item><item><title>Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-32433. Status: Patched. Affects: Erlang/OTP SSH server daemon. Tags: RCE, pre-auth, unauthenticated, SSH, Erlang, OTP, RabbitMQ, CouchDB, ICS, OT, reverse-shell, in-the-wild.</description><category>network</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>SSH</category><category>Erlang</category><category>OTP</category><category>RabbitMQ</category><category>CouchDB</category><category>ICS</category><category>OT</category><category>reverse-shell</category><category>in-the-wild</category></item></channel></rss>