Overview
Contents of this topic will revolve around vulnerabilities that allow remote command execution on a target machine as any users.
π§ Techniques
| File | Created |
|---|
| (incomplete) Argument Injection | June 14, 2026 |
| (incomplete) File Upload Vulnerabilities | May 21, 2026 |
| (incomplete) Living Off The Land | May 21, 2026 |
| (incomplete) OS Command Injection - Linux | May 21, 2026 |
| (incomplete) PHP Archive Deserialization | May 21, 2026 |
| (incomplete) PHP disable_function bypass | May 21, 2026 |
| (incomplete) PHP Generic Gadget Chains | May 21, 2026 |
| (incomplete) PHP Object Injection | May 21, 2026 |
| (incomplete) PHP Session Upload Race Condition | July 15, 2026 |
| (incomplete) PHP-CGI Argument Injection | May 21, 2026 |
| (incomplete) Secure Design Pattern - Upload | May 21, 2026 |
| (incomplete) Server-side Template Injection | May 22, 2026 |
| CVE-2026-24061 | Friday, January 30th 2026, 10:30:50 pm |
| Kubernetes - Kubelet API Anonymous Access | July 27, 2026 |
| MSSQL - xp_cmdshell Command Execution | July 23, 2026 |
| Node.js Inspector Protocol RCE | July 28, 2026 |
| Python - C-Extension Precedence Hijacking | Friday, April 24th 2026, 10:50:15 am |
| Python - Class Pollution | Wednesday, April 15th 2026, 7:52:25 pm |
| React2Shell | July 28, 2026 |
| Reverse Shell Payloads | April 24, 2026 |
π¦ Tech Stack