August 31, 2024MS15-018 Microsoft Internet Explorer 10 and 11 Cross-Domain JavaScript Injection

This Metasploit module exploits a universal cross-site scripting (UXSS) vulnerability found in Internet Explorer 10 and 11. By default, you will steal the cookie from TARGET_URI (which cannot have X-Frame-Options or it will fail). You can also have your o

August 31, 2024NETGEAR Administrator Password Disclosure

This Metasploit module will collect the password for the admin user. The exploit will not complete if password recovery is set on the router. The password is received by passing the token generated from unauth.cgi to passwordrecovered.cgi. This exploit wo

August 31, 2024Xerox Administrator Console Password Extractor

This Metasploit module will extract the management consoles admin password from the Xerox file system using firmware bootstrap injection.

August 31, 2024QNAP NAS/NVR Administrator Hash Disclosure

This Metasploit module exploits combined heap and stack buffer overflows for QNAP NAS and NVR devices to dump the admin (root) shadow hash from memory via an overwrite of __libc_argv[0] in the HTTP-header-bound glibc backtrace. A binary search is performe

August 31, 2024Jenkins Domain Credential Recovery

This Metasploit module will collect Jenkins domain credentials, and uses the script console to decrypt each password if anonymous permission is allowed. It has been tested against Jenkins version 1.590, 1.633, and 1.638.

August 31, 2024Oracle Application Testing Suite Post-Auth DownloadServlet Directory Traversal

This Metasploit module exploits a vulnerability in Oracle Application Testing Suite (OATS). In the Load Testing interface, a remote user can abuse the custom report template selector, and cause the DownloadServlet class to read any file on the server as S

August 31, 2024Pulse Secure VPN Arbitrary File Disclosure

This Metasploit module exploits a pre-auth directory traversal in the Pulse Secure VPN server to dump an arbitrary file. Dumped files are stored in loot. If the "Automatic" action is set, plaintext and hashed credentials, as well as session IDs, will be d

August 31, 2024Apache Tapestry HMAC secret key leak

This exploit finds the HMAC secret key used in Java serialization by Apache Tapestry. This key is located in the file AppModule.class by default and looks like the standard representation of UUID in hex digits (hd) : 6hd-4hd-4hd-4hd-12hd If the HMAC key h

August 31, 2024DarkComet Server Remote File Download

This Metasploit module exploits an arbitrary file download vulnerability in the DarkComet C&C server versions 3.2 and up. The exploit does not need to know the password chosen for the bot/server communication.

August 31, 2024F5 BIG-IP Backend Cookie Disclosure

This Metasploit module identifies F5 BIG-IP load balancers and leaks backend information (pool name, routed domain, and backend servers IP addresses and ports) through cookies inserted by the BIG-IP systems.

Archives
Categories
  • All Exploits 4087
  • Remote Code Execution
  • SQL Injection
  • Command Injection
  • Local File Inclusion
  • Cross Site Scripting
  • Privilege Escalation
  • Denial Of Service
  • Authentication Bypass
  • Buffer Overflow