Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9 MSF:AUXILIARY-GATHER-

Listmonk Insecure Sprig Template Functions Environment Disclosure_MSF:AUXILIARY-GATHER-LISTMONK_ENV_DISCLOSURE-

This module exploits insecure Sprig template functions in Listmonk versions prior to v5.0.2. The env and expandenv functions are enabled ...

N/A N/A METASPLOIT
NONE MSF:EXPLOIT-WINDOWS-

Malicious Windows Script Host Script File (.wsf)_MSF:EXPLOIT-WINDOWS-FILEFORMAT-WINDOWS_SCRIPT_HOST_WSF-

This module creates a Windows Script Host (WSH) Windows Script File (.wsf). Module Options msf > use exploit/windows/fileformat/windows_script_h...

N/A N/A METASPLOIT
NONE MSF:EXPLOIT-OSX-

Mac OS X Persistent Payload Installer_MSF:EXPLOIT-OSX-PERSISTENCE-LAUNCH_PLIST-

This module provides a persistent boot payload by creating a launch item, which can be a LaunchAgent or a LaunchDaemon. LaunchAgents run...

N/A N/A METASPLOIT
NONE MSF:AUXILIARY-FILEFORMAT-

SpecialFolderDatablock – Windows LNK File Special UNC Path NTLM Leak_MSF:AUXILIARY-FILEFORMAT-SPECIALFOLDER_LEAK-

This module creates a malicious Windows shortcut (LNK) file that specifies a special UNC path in SpecialFolderDatablock of Shell Link (.L...

N/A N/A METASPLOIT
NONE MSF:AUXILIARY-FILEFORMAT-

IconEnvironmentDataBlock – Windows LNK File Special UNC Path NTLM Leak_MSF:AUXILIARY-FILEFORMAT-ICON_ENVIRONMENT_DATABLOCK_LEAK-

This module creates a malicious Windows shortcut (LNK) file that specifies a special UNC path in IconEnvironmentDataBlock of Shell Link (...

N/A N/A METASPLOIT
NONE MSF:AUXILIARY-FILEFORMAT-

Windows Shortcut (LNK) Padding_MSF:AUXILIARY-FILEFORMAT-DATABLOCK_PADDING_LNK-

This module generates Windows LNK (shortcut) file that can execute arbitrary commands. The LNK file uses environment variables and execut...

N/A N/A METASPLOIT
NONE MSF:AUXILIARY-FILEFORMAT-

Right-Click Execution – Windows LNK File Special UNC Path NTLM Leak_MSF:AUXILIARY-FILEFORMAT-ENVIRONMENT_VARIABLE_DATABLOCK_LEAK-

This module creates a malicious Windows shortcut (LNK) file that specifies a special UNC path in EnvironmentVariableDataBlock of Shell...

N/A N/A METASPLOIT
NONE MSF:EXPLOIT-WINDOWS-

Windows Silent Process Exit Persistence_MSF:EXPLOIT-WINDOWS-PERSISTENCE-IMAGE_EXEC_OPTIONS-

Windows allows you to set up a debug process when a process exits. This module uploads a payload and declares that it is...

N/A N/A METASPLOIT
NONE MSF:EXPLOIT-LINUX-

Service SystemD override.conf Persistence_MSF:EXPLOIT-LINUX-PERSISTENCE-INIT_SYSTEMD_OVERRIDE-

This module will create an override.conf file for a SystemD service on the box. The ExecStartPost hook is used to launch the payload...

N/A N/A METASPLOIT
CRITICAL 10 MSF:EXPLOIT-UNIX-

FreePBX ajax.php unuthenticated SQLi to RCE_MSF:EXPLOIT-UNIX-HTTP-FREEPBX_UNAUTH_SQLI_TO_RCE-

This module exploits an unauthenticated SQL injection flaw in FreePBX prior to versions 15.0.66, 16.0.89, and...

N/A N/A METASPLOIT