August 31, 2024Firefox PDF.js Browser File Theft

This Metasploit module abuses an XSS vulnerability in versions prior to Firefox 39.0.3, Firefox ESR 38.1.1, and Firefox OS 2.2 that allows arbitrary files to be stolen. The vulnerability occurs in the PDF.js component, which uses Javascript to render a PD

August 31, 2024HTTP Client LAN IP Address Gather

This Metasploit module retrieves a browsers network interface IP addresses using WebRTC.

August 31, 2024Android Browser Open in New Tab Cookie Theft

In Androids stock AOSP Browser application and WebView component, the "open in new tab" functionality allows a file URL to be opened. On versions of Android before 4.4, the path to the sqlite cookie database could be specified. By saving a cookie containi

August 31, 2024Network Shutdown Module sort_values Credential Dumper

This Metasploit module will extract user credentials from Network Shutdown Module versions 3.21 and earlier by exploiting a vulnerability found in lib/dbtools.inc, which uses unsanitized user input inside a eval() call. Please note that in order to extrac

August 31, 2024Huawei Datacard Information Disclosure

This Metasploit module exploits an unauthenticated information disclosure vulnerability in Huawei SOHO routers. The module will gather information by accessing the /api pages where authentication is not required, allowing configuration changes as well as

August 31, 2024Cisco PVC2300 POE Video Camera Configuration Download

This Metasploit module exploits an information disclosure vulnerability in Cisco PVC2300 cameras in order to download the configuration file containing the admin credentials for the web interface. The module first performs a basic check to see if the targ

August 31, 2024DNS Record Scanner and Enumerator

This Metasploit module can be used to gather information about a domain from a given DNS server by performing various DNS queries such as zone transfers, reverse lookups, SRV record brute forcing, and other techniques.

August 31, 2024Adobe ColdFusion Unauthenticated Arbitrary File Read

This Metasploit module exploits a remote unauthenticated deserialization of untrusted data vulnerability in Adobe ColdFusion 2021 Update 5 and earlier as well as ColdFusion 2018 Update 15 and earlier, in order to read an arbitrary file from the server. To

August 31, 2024SSL Labs API Client

This Metasploit module is a simple client for the SSL Labs APIs, designed for SSL/TLS assessment during a penetration test.

August 31, 2024Jenkins cli Ampersand Replacement Arbitrary File Read

This Metasploit module utilizes the Jenkins cli protocol to run the help command. The cli is accessible with read-only permissions by default, which are all thats required. Jenkins cli utilizes args4js parseArgument, which calls expandAtFiles to replace a

Archives
Categories
  • All Exploits 4087
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow