Ross ROSS = Recommend OSS · open-source software intelligence for agents

cseroad/Exp-Tools

一款集成高危漏洞exp的实用性工具 observed · 2026-08-28

github.com/cseroad/Exp-Tools observed · 2026-08-28

Health v2 · maintenance only

21/100

  • Activity 0
  • Release rhythm 8
  • Longevity 91

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1274
  • days_rel: 665
  • days_push: 665
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1316 stars · 85 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise software, primarily OA (Office Automation) systems like Yonyou, Weaver, Landray, Wanhu, FanRuan, Seeyon, Tongda, Hongfan, Jinhe, Kingdee, Glodon, and Huatian. It provides a JavaFX-based interface for testing command execution, file upload, SQL injection, deserialization, and authentication bypass vulnerabilities across 12+ OA product families.

Use cases

  • test OA systems for known file upload vulnerabilities
  • verify command execution exploits in Chinese enterprise software
  • check deserialization vulnerabilities in Yonyou NC and U8 products
  • assess Weaver ecology and eoffice for exploitable flaws
  • validate unauthorized access and password reset issues in Seeyon and Tongda OA
  • run authorized penetration tests against FanRuan report servers

When to choose

  • you need a consolidated exploit toolkit for Chinese OA and enterprise software during authorized engagements
  • you want pre-built, tested exploit modules rather than writing PoCs from scratch
  • you are assessing environments running Yonyou, Weaver, Landray, Seeyon, or similar Chinese OA products
  • you prefer a JavaFX GUI tool that runs on JDK 1.8 without complex setup

When to avoid

  • you need a general-purpose vulnerability scanner rather than targeted exploit verification
  • your targets are not Chinese enterprise/OA software
  • you require a fully maintained tool with active security patches and formal licensing
  • unauthorized testing is your intent - this tool explicitly prohibits it

Facets

cli-tool · maturity active

security penetration-testing vulnerability-scanning security penetration-testing developer-tools cross-platform cli jvm exploit-framework vulnerability-exploitation penetration-testing oa-systems chinese-software red-team security-testing rce file-upload deserialization javafx authorized-testing-only exploitation command-line

1 source

Member repositories

RepositoryRoleHealth v2
cseroad/Exp-Toolsmain21

For agents

markdown · JSON · MCP: product_card(name="cseroad/Exp-Tools")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem