m3m0o / metabase-pre-auth-rce-poc
This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.
☆26Updated 6 months ago
Alternatives and similar repositories for metabase-pre-auth-rce-poc:
Users that are interested in metabase-pre-auth-rce-poc are comparing it to the libraries listed below
- This repo is a PoC with to exploit CVE-2023-51467 and CVE-2023-49070 preauth RCE vulnerabilities found in Apache OFBiz.☆73Updated 10 months ago
- Joomla! < 4.2.8 - Unauthenticated information disclosure☆82Updated last year
- CVE-2023-2255 Libre Office☆57Updated last year
- Script to retrieve the master password of a keepass database <= 2.53.1☆95Updated 9 months ago
- Joomla login bruteforce☆60Updated 6 months ago
- GameOver(lay) Ubuntu Privilege Escalation☆122Updated last year
- Reverse Shell POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253), PHP Code Injection☆38Updated 8 months ago
- A proof of concept for CVE-2023–1326 in apport-cli 2.26.0☆17Updated last year
- Obtain the passphrase of a private key (id_rsa), this tool uses the ssh-keygen binary to perform a brute force attack until a successful …☆64Updated this week
- CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit☆58Updated 4 months ago
- POC for CVE-2021-41091☆64Updated last year
- Nibbleblog 4.0.3 - Arbitrary File Upload (CVE-2015-6967)☆13Updated 3 years ago
- KeePass 2.X dumper (CVE-2023-32784)☆17Updated last year
- A webshell plugin and interactive shell for pentesting a Joomla website.☆46Updated 2 years ago
- A couple of different scripts, made to automate attacks against NoSQL databases.☆62Updated 10 months ago
- Interact with Hackthebox using your terminal - Be faster and more competitive !☆92Updated last month
- ☆38Updated 4 months ago
- Ghostscript command injection vulnerability PoC (CVE-2023-36664)☆117Updated last year
- Bad scripts I made doing CTF's☆21Updated last year
- WonderCMS Authenticated RCE - CVE-2023-41425☆25Updated last month
- Openfire Console Authentication Bypass Vulnerability with RCE plugin☆48Updated 10 months ago
- Collection of useful pre-compiled .NET binaries or other executables for penetration testing Windows Active Directory environments☆112Updated last month
- ☆29Updated last year
- This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220☆22Updated 6 months ago
- SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions…☆65Updated 3 months ago
- Pentesting Apache Tomcat 101☆11Updated last year
- ☆59Updated last year
- Vulnerabilities Exploitation On Ubuntu 22.04☆36Updated last year
- JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit☆44Updated 8 months ago
- Werkzeug password cracker☆14Updated 2 months ago