Share
## https://sploitus.com/exploit?id=3A2F690C-6191-5CF2-A787-8BDEB3720B9F
# RCE Nextcloud โ€” Cache Poisoning โ†’ Pre-Auth RCE

Reproducible proof-of-concept for an **unauthenticated remote code execution** in Nextcloud
Server 33.0.1 (unsafe deserialization in the TaskProcessing cache + exposed password-less Redis).
Companion material for the article.

Choose your language / Escolha o idioma:

- ๐Ÿ‡ง๐Ÿ‡ท **Portuguรชs** โ†’ [`pt-br/`](pt-br/)
- ๐Ÿ‡ฌ๐Ÿ‡ง **English** โ†’ [`en/`](en/)

Each folder is self-contained: the two attack scenarios (`01-same-machine/` and
`02-lan-attack/`) and the lab (`lab/`).

> โš ๏ธ For educational/research use in a lab you own. See [`pt-br/DISCLAIMER.md`](pt-br/DISCLAIMER.md)
> (bilingual).