This is your work, valued

dollarboysushil

Expert
@dollarboysushil

CPTS | Penetration Tester | Red Teamer

oscp-cpts-notes. Notes for OSCP & CPTS.

125

CCNA-200-301. Following Jeremy's IT Lab | Free CCNA 200-301 | Complete Course 2023

37

CVE-2025-24893-XWiki-Unauthenticated-RCE-Exploit-POC. CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki (versions < 15.10.11, 16.4.1, 16.5.0RC1) caused by improper handling of Groovy expressions in the SolrSearch macro.

17

CVE-2024-32019-Netdata-ndsudo-PATH-Vulnerability-Privilege-Escalation. CVE-2024-32019 is a high-severity local privilege escalation vulnerability in Netdata (versions >= 1.44.0-60 < 1.45.3), caused by insecure use of the PATH variable in the ndsudo SUID binary, allowing attackers to execute arbitrary commands as root.

14

Dolibarr-17.0.0-Exploit-CVE-2023-30253. In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection bypassing the application restrictions.

9

CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC. CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated remote code execution via the XMLRPC interface.

8

Linux-Privilege-Escalation-CVE-2025-27591. CVE-2025-27591 is a known privilege escalation vulnerability in the Below service (version < v0.9.0)

7

Privilege-Escalation-PoC-Terraform-sudo-Exploit. PoC showing Linux privilege escalation via sudo Terraform. By abusing provider_installation dev_overrides and TF_CLI_CONFIG_FILE, a malicious provider script runs as root, allowing creation of a SUID root shell.

7

OSCP-guide. OSCP Guide

3

CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE. PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.

3

web-application-pentesting. A curated repository of web application penetration testing notes, labs, and walkthroughs from PortSwigger Academy and real-world exercises. Ideal for anyone learning bug bounty hunting, web app security, and practical pentesting techniques.

3

CVE-2025-49132-Pterodactyl-Panel-Unauthenticated-Remote-Code-Execution-RCE-. PoC exploit for CVE-2025-49132 (GHSA-24wv-6c99-f843) – Unauthenticated Remote Code Execution in Pterodactyl Panel ≤ 1.11.10

3

Tools-with-Python-Black-Hat-Python-2nd-Edition-. Black Hat Python 2nd Edition

2

100-days-of-Code-Python. 100 Days of Code: The Complete Python Pro Bootcamp for 2023

1

discord-bot. [PUBLIC] discord bot by dollarboysushil

1

Chamilo-LMS-Unauthenticated-File-Upload-CVE-2023-4220. Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

1

return-youtube-dislike. Chrome extension to return youtube dislikes

1

oscp-pre-preparation-plan-and-notes. My OSCP Pre-Preparation Phase. I'm not sure if I'll be able to afford the exam but what count's trying and learning things. I'm gonna give it a try. [Start Date: 21st March 2022]

1