# zhzyker/exphub

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本，最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340

Repository: https://github.com/zhzyker/exphub
Canonical: https://ross.abutalabs.com/products/exphub
Language: Python
License Family: other
Topics: weblogic, tomcat, exploit, poc, vulnerability, exp, webshell, drupal, getshell, nexus, cve-2020-10199, cve-2020-2555, cve-2020-11444, cve-2020-10204, cve-2020-1938, cve-2020-2883, cve-2020-2551, cve-2020-5902, cve-2020-14882
Last push: 2021-04-04T09:13:57+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2345, "days_push": 1977, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4291, forks 1081 (observed 2026-08-28T04:08:41.404483+00:00)

## What it is
Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, Struts2, Tomcat, Fast, Nexus, Solr, JBoss, and Drupal. Each script verifies (poc) or exploits (exp/rce/shell/webshell) a specific vulnerability.

## Use cases
- verify whether a server is vulnerable to a specific CVE
- exploit a Weblogic deserialization RCE to get a reverse shell
- upload a webshell to a vulnerable Tomcat instance
- test Fast versions for deserialization vulnerabilities
- run a quick poc check during a penetration test

## When to choose
- you need a ready-made, tested exploit script for a specific CVE in Weblogic, Struts2, Tomcat, Fast, or similar middleware
- you want lightweight single-purpose scripts rather than a full scanning framework
- you are doing authorized penetration testing or CTF challenges against these products

## When to avoid
- you need an actively maintained tool with new CVE coverage (development stopped in 2021; the author moved to vulmap)
- you want a unified scanner rather than one script per vulnerability
- you require a project with a clear license for commercial or compliance-sensitive use

## Facets
- artifact type: library
- maturity: abandoned
- function: penetration-testing, security, vulnerability-scanning
- domain: security, penetration-testing, developer-tools
- platform: python, cli
- tags: exploit-scripts, poc, cve, rce, webshell, getshell, red-team, vulnerability-exploitation, linux

## Member repositories
- zhzyker/exphub (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:41.404483+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:21:53.916591+00:00, confidence not recorded.
  - readme: https://github.com/zhzyker/exphub (fetched 2026-08-28T04:08:41.404483+00:00, sha 22ebb650b17c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
