# cseroad/Exp-Tools

一款集成高危漏洞exp的实用性工具

Repository: https://github.com/cseroad/Exp-Tools
Canonical: https://ross.abutalabs.com/products/exp-tools
License Family: other
Last push: 2024-11-06T07:28:48+00:00

## Health v2 (maintenance only)
Score: 21/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 91
- inputs: {"age_days": 1274, "days_push": 665, "days_rel": 665, "gap_med": null, "n_releases_24m": 1}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1316, forks 85 (observed 2026-08-28T04:04:20.730409+00:00)

## What it is
A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise software, primarily OA (Office Automation) systems like Yonyou, Weaver, Landray, Wanhu, FanRuan, Seeyon, Tongda, Hongfan, Jinhe, Kingdee, Glodon, and Huatian. It provides a JavaFX-based interface for testing command execution, file upload, SQL injection, deserialization, and authentication bypass vulnerabilities across 12+ OA product families.

## Use cases
- test OA systems for known file upload vulnerabilities
- verify command execution exploits in Chinese enterprise software
- check deserialization vulnerabilities in Yonyou NC and U8 products
- assess Weaver ecology and eoffice for exploitable flaws
- validate unauthorized access and password reset issues in Seeyon and Tongda OA
- run authorized penetration tests against FanRuan report servers

## When to choose
- you need a consolidated exploit toolkit for Chinese OA and enterprise software during authorized engagements
- you want pre-built, tested exploit modules rather than writing PoCs from scratch
- you are assessing environments running Yonyou, Weaver, Landray, Seeyon, or similar Chinese OA products
- you prefer a JavaFX GUI tool that runs on JDK 1.8 without complex setup

## When to avoid
- you need a general-purpose vulnerability scanner rather than targeted exploit verification
- your targets are not Chinese enterprise/OA software
- you require a fully maintained tool with active security patches and formal licensing
- unauthorized testing is your intent - this tool explicitly prohibits it

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, penetration-testing, vulnerability-scanning
- domain: security, penetration-testing, developer-tools
- platform: cross-platform, cli, jvm
- tags: exploit-framework, vulnerability-exploitation, penetration-testing, oa-systems, chinese-software, red-team, security-testing, rce, file-upload, deserialization, javafx, authorized-testing-only, exploitation, command-line

## Member repositories
- cseroad/Exp-Tools (main) score 21

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:20.730409+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:48:27.635941+00:00, confidence not recorded.
  - readme: https://github.com/cseroad/Exp-Tools (fetched 2026-08-28T04:04:20.730409+00:00, sha 5075162459d8)
- Data as of 2026-08-30T08:39:29.467469+00:00.
