# zhzyker/exphub

**Attribution required: if you use, quote, or summarise this content, you must credit and link back to [awesome-repositories.com](https://awesome-repositories.com/repository/zhzyker-exphub).**

_How this analysis was created: the description and tags below were written by an AI model that read this project's README and public documentation pages; stars, license and language come straight from the GitHub API. The model does not read the source code._

4,282 stars · 1,082 forks · Python

## Links

- GitHub: https://github.com/zhzyker/exphub
- awesome-repositories: https://awesome-repositories.com/repository/zhzyker-exphub.md

## Topics

`cve-2020-10199` `cve-2020-10204` `cve-2020-11444` `cve-2020-14882` `cve-2020-1938` `cve-2020-2551` `cve-2020-2555` `cve-2020-2883` `cve-2020-5902` `drupal` `exp` `exploit` `getshell` `nexus` `poc` `tomcat` `vulnerability` `weblogic` `webshell`

## Description

Exphub is a CVE exploit script library and enterprise software vulnerability suite designed to verify and exploit known security flaws in server environments such as WebLogic, Struts2, Tomcat, and JBoss. It functions as a remote code execution toolkit and a web shell deployment framework for triggering unauthorized command execution and establishing persistent access on remote systems.

The project includes specialized utilities for internal network reconnaissance, specifically using server-side request forgery to scan for open ports and services. It further provides mechanisms for bypassing access controls and performing unauthorized file reads and uploads.

The suite covers broad capability areas including vulnerability assessment, penetration testing, and the execution of proof-of-concept scripts to confirm the presence of security vulnerabilities.

## Tags

### Security & Cryptography

- [Remote Code Execution Tools](https://awesome-repositories.com/f/security-cryptography/remote-code-execution-tools.md) — Provides a toolkit designed to achieve and manage arbitrary code execution on remote target systems. ([source](https://github.com/zhzyker/exphub/tree/master/drupal))
- [Vulnerability Proofs of Concept](https://awesome-repositories.com/f/security-cryptography/vulnerability-proofs-of-concept.md) — Provides a library of executable proof-of-concept scripts to demonstrate the exploitability of specific CVEs.
- [Deserialization Exploits](https://awesome-repositories.com/f/security-cryptography/deserialization-exploits.md) — Implements attacks that execute arbitrary commands via serialized object reconstruction in server environments.
- [Exploit Payload Deployments](https://awesome-repositories.com/f/security-cryptography/exploit-payload-deployments.md) — Ships mechanisms for transferring and executing offensive exploit payloads on remote target systems.
- [Network Vulnerability Scanning](https://awesome-repositories.com/f/security-cryptography/network-vulnerability-scanning.md) — Uses server-side request forgery to identify open ports and services on a local network. ([source](https://github.com/zhzyker/exphub/blob/master/weblogic/))
- [Penetration Testing Frameworks](https://awesome-repositories.com/f/security-cryptography/penetration-testing-frameworks.md) — Provides an automated framework for discovering and exploiting security weaknesses in enterprise software.
- [Proof of Concept Execution](https://awesome-repositories.com/f/security-cryptography/proof-of-concept-execution.md) — Runs curated proof-of-concept scripts to verify and exploit security flaws across various software environments. ([source](https://github.com/zhzyker/exphub/search))
- [Web Shells](https://awesome-repositories.com/f/security-cryptography/web-shells.md) — Uploads and executes a script on a remote server to establish persistent access and command control. ([source](https://github.com/zhzyker/exphub/tree/master/weblogic))
- [Access Control Bypasses](https://awesome-repositories.com/f/security-cryptography/access-control-bypasses.md) — Implements mechanisms to modify credentials or exploit privilege escalation to gain unauthorized entry. ([source](https://github.com/zhzyker/exphub#readme))
- [Automated Vulnerability Detection](https://awesome-repositories.com/f/security-cryptography/automated-vulnerability-detection.md) — Scans target URLs to automatically identify security weaknesses and known vulnerabilities in web services. ([source](https://github.com/zhzyker/exphub/tree/master/drupal))
- [Path Traversal Exploits](https://awesome-repositories.com/f/security-cryptography/path-traversal-exploits.md) — Provides capabilities to read sensitive system files by escaping directory constraints via path manipulation.
- [Remote Code Execution Testing](https://awesome-repositories.com/f/security-cryptography/remote-code-execution-testing.md) — Analyzes target software to detect vulnerabilities that allow an attacker to execute arbitrary remote code. ([source](https://github.com/zhzyker/exphub/tree/master/struts2))
- [SSRF-Based Reconnaissance](https://awesome-repositories.com/f/security-cryptography/ssrf-based-reconnaissance.md) — Includes specialized utilities to scan internal network ports and services using server-side request forgery.
- [Network Reconnaissance Tools](https://awesome-repositories.com/f/security-cryptography/vulnerability-assessment-testing/network-reconnaissance-tools.md) — Scans internal networks to identify active services and potential entry points using SSRF.

### Part of an Awesome List

- [Port Scanning](https://awesome-repositories.com/f/awesome-lists/devtools/port-scanning.md) — Identifies active hosts and open services on internal networks by leveraging SSRF vulnerabilities. ([source](https://github.com/zhzyker/exphub/tree/master/weblogic))
- [Port Scanning Tools](https://awesome-repositories.com/f/awesome-lists/devtools/port-scanning-tools.md) — Identifies open ports and network services within internal networks using server-side request forgery. ([source](https://github.com/zhzyker/exphub/blob/master/readme.md))
- [Proof Of Concept Exploits](https://awesome-repositories.com/f/awesome-lists/security/proof-of-concept-exploits.md) — Maintains a collection of security research and functional exploit code for various CVEs.
- [Software Vulnerability Exploits](https://awesome-repositories.com/f/awesome-lists/security/software-vulnerability-exploits.md) — Provides a library of proof-of-concept exploits targeting enterprise server environments.
- [Vulnerability Exploitation Frameworks](https://awesome-repositories.com/f/awesome-lists/security/vulnerability-exploitation-frameworks.md) — Provides a framework for detecting and exploiting security flaws in middleware and application frameworks. ([source](https://github.com/zhzyker/exphub/blob/master/struts2))
- [Web Application Exploits](https://awesome-repositories.com/f/awesome-lists/security/vulnerability-exploitation-frameworks/web-application-exploits.md) — Employs specialized payloads to verify web-layer vulnerabilities and gain unauthorized server access.
- [Web Shells](https://awesome-repositories.com/f/awesome-lists/security/web-shells.md) — Deploys web shells to compromised servers to establish persistent remote access and command control. ([source](https://github.com/zhzyker/exphub/blob/master/readme.md))
- [Command Injection Exploiters](https://awesome-repositories.com/f/awesome-lists/security/vulnerability-exploitation-frameworks/batch-exploit-execution/automated-exploit-execution/command-injection-exploiters.md) — Automates the exploitation of command injection vulnerabilities to execute arbitrary commands on target servers. ([source](https://github.com/zhzyker/exphub/tree/master/fastjson))
- [Vulnerability Exploits](https://awesome-repositories.com/f/awesome-lists/security/vulnerability-exploits.md) — Executes proof-of-concept exploits to confirm the presence of security flaws in server environments like JBoss. ([source](https://github.com/zhzyker/exphub/tree/master/jboss))
- [Security References](https://awesome-repositories.com/f/awesome-lists/learning/security-references.md) — Repository of exploit proof-of-concepts.
- [Vulnerability Exploitation](https://awesome-repositories.com/f/awesome-lists/security/vulnerability-exploitation.md) — Centralized repository for various application server exploits.

### Development Tools & Productivity

- [Web Shell Executions](https://awesome-repositories.com/f/development-tools-productivity/shell-command-execution/web-based-command-interfaces/web-shell-executions.md) — Deploys scripts on compromised servers to create permanent HTTP interfaces for remote command execution.
- [Deployment Frameworks](https://awesome-repositories.com/f/development-tools-productivity/shell-command-execution/web-based-command-interfaces/web-shell-executions/deployment-frameworks.md) — Provides a framework for uploading and establishing persistent web-based backdoors on remote compromised systems.

### DevOps & Infrastructure

- [Remote Command Execution](https://awesome-repositories.com/f/devops-infrastructure/remote-command-execution.md) — Triggers unauthorized arbitrary command execution on target systems by leveraging deserialization or plugin flaws. ([source](https://github.com/zhzyker/exphub#readme))

### System Administration & Monitoring

- [Vulnerability Detection](https://awesome-repositories.com/f/system-administration-monitoring/remote-command-execution/vulnerability-detection.md) — Checks target servers for known remote command execution vulnerabilities using proof-of-concept scripts. ([source](https://github.com/zhzyker/exphub/tree/master/weblogic))

### Networking & Communication

- [Port Scanners](https://awesome-repositories.com/f/networking-communication/port-scanners.md) — Identifies open network ports and services by leveraging server-side request forgery.

### Web Development

- [Directory Traversal Exploits](https://awesome-repositories.com/f/web-development/api-management-tools/api-development-management/web-apis/file-reading/directory-traversal-exploits.md) — Accesses sensitive files from target servers by exploiting path traversal and unauthorized reading flaws. ([source](https://github.com/zhzyker/exphub#readme))
- [Arbitrary File Uploads](https://awesome-repositories.com/f/web-development/web-file-transfer-utilities/arbitrary-file-uploads.md) — Provides capabilities to upload unauthorized files to remote servers to achieve remote code execution. ([source](https://github.com/zhzyker/exphub/tree/master/weblogic))
