A collection of PDF-based security research PoCs demonstrating different PDF abuse cases and attack techniques.
-
calculatorRCE.pdfDemonstrates PDF JavaScript abuse that can trigger Calculator RCE in vulnerable PDF viewers. -
cookie.pdf/cookieprompt.pdfDemonstrates PDF-based techniques for interacting with or exposing browser-related cookie information. -
domain.pdfDisplays a domain popup when the PDF is opened, demonstrating basic PDF-based domain interaction.
For a detailed explanation of PDF.js exploitation, including a real-world website PoC for CVE-2024-4367, check out the Medium article:
👉 PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
Use these PoCs only in environments you own or have explicit permission to test.