WP-Shell3r v0.3 â WordPress Shell Uploader
â Plugin / Direct / File Manager / Plugin Editor upload
â WAF & email verification bypass
â Auto admin creation
â Async GUI + retry system
â Multi-format site list support
ââââââââââââââââââââ
đ Site List Formats
ââââââââââââââââââââ
site|user|pass
site:user:pass
site;user;pass
site/wp-login.php:user:pass
site/wp-login.php#user@pass
âĸ http:// optional â auto-added
âĸ Duplicates removed automatically
âĸ Encodings: UTF-8 / Latin-1 / CP1252
Trial version : here
ââââââââââââââââââââ
đ° Price: DM
đ @blackscriptx
đŠ Contact: @Moonlightcrow
ââââââââââââââââââââ
â ī¸ For authorized penetration testing only
â Plugin / Direct / File Manager / Plugin Editor upload
â WAF & email verification bypass
â Auto admin creation
â Async GUI + retry system
â Multi-format site list support
ââââââââââââââââââââ
đ Site List Formats
ââââââââââââââââââââ
site|user|pass
site:user:pass
site;user;pass
site/wp-login.php:user:pass
site/wp-login.php#user@pass
âĸ http:// optional â auto-added
âĸ Duplicates removed automatically
âĸ Encodings: UTF-8 / Latin-1 / CP1252
Trial version : here
ââââââââââââââââââââ
đ° Price: DM
đ @blackscriptx
đŠ Contact: @Moonlightcrow
ââââââââââââââââââââ
â ī¸ For authorized penetration testing only
â đŦ Mailer Tester â by Who Knows
Mass-test your Leaf PHPMailer panels in seconds.
â Paste 100s of mailer URLs â tested concurrently
đ Live stats: Done / Left / OK / Failed in real time
âĄī¸ Progress bar updates as each result comes in
âšī¸ Stop anytime with one click
đ Clean web UI â runs locally on your machine
Built with Python (FastAPI) + Chrome TLS impersonation
so servers can't fingerprint-block the requests.
How to run:
python main.py
â open http://localhost:8765
Link : here
đ https://t.me/Moonlightcrow
Mass-test your Leaf PHPMailer panels in seconds.
â Paste 100s of mailer URLs â tested concurrently
đ Live stats: Done / Left / OK / Failed in real time
âĄī¸ Progress bar updates as each result comes in
âšī¸ Stop anytime with one click
đ Clean web UI â runs locally on your machine
Built with Python (FastAPI) + Chrome TLS impersonation
so servers can't fingerprint-block the requests.
How to run:
pip install -r requirements.txtpython main.py
â open http://localhost:8765
Link : here
đ https://t.me/Moonlightcrow
đĨ1
xleet-main.py
34.2 KB
đ xLeet Shell Uploader v3.0
GUI tool for mass-uploading shells to xLeet
Features:
âĸ đĒ JSON Cookie Loader â paste exported browser cookies, tokens auto-extracted
âĸ âĄī¸ Multi-threaded uploads â configurable worker count (1â20)
âĸ đ° Price control â set min/max range or randomize per shell
âĸ đ Auto-retry â exponential backoff, skips 4xx auth errors instantly
âĸ âī¸ Persistent settings â URL, tokens, performance saved between sessions
âĸ đ Clean stop â non-blocking cancel, saves progress
âĸ đ Live stats â success / failed / remaining counters
âĸ đ§ Configurable domain â change target URL without editing code
@Moonlightcrow
GUI tool for mass-uploading shells to xLeet
Features:
âĸ đĒ JSON Cookie Loader â paste exported browser cookies, tokens auto-extracted
âĸ âĄī¸ Multi-threaded uploads â configurable worker count (1â20)
âĸ đ° Price control â set min/max range or randomize per shell
âĸ đ Auto-retry â exponential backoff, skips 4xx auth errors instantly
âĸ âī¸ Persistent settings â URL, tokens, performance saved between sessions
âĸ đ Clean stop â non-blocking cancel, saves progress
âĸ đ Live stats â success / failed / remaining counters
âĸ đ§ Configurable domain â change target URL without editing code
pip install PySide6 requests brotli@Moonlightcrow
â¤1
CVE-2026-48907.py
15.1 KB
đĨ CVE-2026-48907 â JCE Joomla Unauthenticated RCE Scanner
Exploit for the JCE (JoomlaContentEditor) plugin remote code execution vulnerability.
âī¸ Features:
âĸ Async engine (aiohttp) â high concurrency, low overhead
âĸ Auto CSRF token extraction
âĸ Multi-payload strategy (direct .php + GIF rename bypass)
âĸ Only saves CONFIRMED shells (PHP code actually executes)
âĸ Results saved to: joom-shell.txt
đ Usage:
python CVE-2026-48907.py
â Enter targets file & concurrency
=> Who Knows
đĸ Channel : https://t.me/Moonlightcrow
For educational and authorized testing only.
Exploit for the JCE (JoomlaContentEditor) plugin remote code execution vulnerability.
âī¸ Features:
âĸ Async engine (aiohttp) â high concurrency, low overhead
âĸ Auto CSRF token extraction
âĸ Multi-payload strategy (direct .php + GIF rename bypass)
âĸ Only saves CONFIRMED shells (PHP code actually executes)
âĸ Results saved to: joom-shell.txt
đ Usage:
pip install aiohttp aiofiles coloramapython CVE-2026-48907.py
â Enter targets file & concurrency
=> Who Knows
đĸ Channel : https://t.me/Moonlightcrow
For educational and authorized testing only.
â¤2
Adminer 5.4.2 â MSSQL TraceFile RCE
âââ VULNERABILITY âââ
Adminer 5.4.2 MSSQL driver passes auth[server]
directly into the PDO DSN. Semicolon-delimited
options are parsed by ODBC â injecting:
TraceFile=up.php;TraceOn=1
causes ODBC to write a trace file to webroot.
auth[username] lands as UID={<value>} in the
trace â inject PHP webshell there.
âââ RUN âââ
python Adminer-0day.py siteList.txt
Download-Link : Here
âââ VULNERABILITY âââ
Adminer 5.4.2 MSSQL driver passes auth[server]
directly into the PDO DSN. Semicolon-delimited
options are parsed by ODBC â injecting:
TraceFile=up.php;TraceOn=1
causes ODBC to write a trace file to webroot.
auth[username] lands as UID={<value>} in the
trace â inject PHP webshell there.
pip install aiohttp colorama
âââ RUN âââ
python Adminer-0day.py siteList.txt
Download-Link : Here
â¤4
force-login.php
348 B
WordPress Force Login(2021' trick) to wp-admin via Shell