Metabase是美国Metabase公司的一个开源数据分析平台。 Metabase 0.46.6.1之前版本和Metabase Enterprise 1.46.6.1之前版本存在安全漏洞,该漏洞源于允许攻击者以运行该服务的权限在服务器上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/adriyansyah-mf/CVE-2023-38646--Metabase- | POC Details |
| 2 | For educational purposes only | https://github.com/Pumpkin-Garden/POC_Metabase_CVE-2023-38646 | POC Details |
| 3 | Metabase Pre-auth RCE (CVE-2023-38646)!! | https://github.com/0xrobiul/CVE-2023-38646 | POC Details |
| 4 | Remote Code Execution on Metabase CVE-2023-38646 | https://github.com/Chocapikk/CVE-2023-38646 | POC Details |
| 5 | None | https://github.com/Xuxfff/CVE-2023-38646-Poc | POC Details |
| 6 | POC for CVE-2023-38646 | https://github.com/securezeron/CVE-2023-38646 | POC Details |
| 7 | Tools to exploit metabase CVE-2023-38646 | https://github.com/lazysec0x21/CVE-2023-38646 | POC Details |
| 8 | Proof of Concept for CVE-2023-38646 | https://github.com/Zenmovie/CVE-2023-38646 | POC Details |
| 9 | Metabase Pre-auth RCE | https://github.com/shamo0/CVE-2023-38646-PoC | POC Details |
| 10 | CVE-2023-38646-POC | https://github.com/fidjiw/CVE-2023-38646-POC | POC Details |
| 11 | None | https://github.com/Any3ite/cve-2023-38646-metabase-ReverseShell | POC Details |
| 12 | Automatic Tools For Metabase Exploit Known As CVE-2023-38646 | https://github.com/robotmikhro/CVE-2023-38646 | POC Details |
| 13 | Metabase Pre-auth RCE (CVE-2023-38646) | https://github.com/kh4sh3i/CVE-2023-38646 | POC Details |
| 14 | CVE-2023-38646 (Pre-Auth RCE in Metabase) | https://github.com/joaoviictorti/CVE-2023-38646 | POC Details |
| 15 | None | https://github.com/yxl2001/CVE-2023-38646 | POC Details |
| 16 | CVE-2023-38646 Pre-Auth RCE in Metabase | https://github.com/alexandre-pecorilla/CVE-2023-38646 | POC Details |
| 17 | Metabase H2 远程代码执行漏洞(CVE-2023-38646) | https://github.com/CN016/Metabase-H2-CVE-2023-38646- | POC Details |
| 18 | CVE-2023-38646 Metabase RCE | https://github.com/Boogipop/MetabaseRceTools | POC Details |
| 19 | CVE-2023-38646 Metabase 0.46.6 exploit | https://github.com/SUT0L/CVE-2023-38646 | POC Details |
| 20 | CVE-2023-38646 Unauthenticated RCE vulnerability in Metabase | https://github.com/nickswink/CVE-2023-38646 | POC Details |
| 21 | None | https://github.com/passwa11/CVE-2023-38646 | POC Details |
| 22 | None | https://github.com/threatHNTR/CVE-2023-38646 | POC Details |
| 23 | None | https://github.com/asepsaepdin/CVE-2023-38646 | POC Details |
| 24 | Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646) | https://github.com/Pyr0sec/CVE-2023-38646 | POC Details |
| 25 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2. | https://github.com/birdm4nw/CVE-2023-38646 | POC Details |
| 26 | RCE Exploit for CVE-2023-38646 | https://github.com/AnvithLobo/CVE-2023-38646 | POC Details |
| 27 | Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection | https://github.com/Red4mber/CVE-2023-38646 | POC Details |
| 28 | Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2. | https://github.com/junnythemarksman/CVE-2023-38646 | POC Details |
| 29 | A crappy exploit script written for CVE-2023-38646. It works about as well as peace treaties between Israel and Hamas. | https://github.com/Itrekr/CVE-2023-38646-Crapsploit | POC Details |
| 30 | Metabase Pre-Auth RCE POC | https://github.com/Mrunalkaran/CVE-2023-38646 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-3811 | 6.3 MEDIUM | Hospital Management System patientprofile.php sql injection |
| CVE-2023-3810 | 6.3 MEDIUM | Hospital Management System patientappointment.php sql injection |
| CVE-2023-3809 | 6.3 MEDIUM | Hospital Management System patient.php sql injection |
| CVE-2023-3808 | 6.3 MEDIUM | Hospital Management System patientforgotpassword.php sql injection |
| CVE-2023-3603 | 3.1 LOW | Processing sftp server read may cause null dereference |
| CVE-2023-38632 | async-sockets-cpp 缓冲区错误漏洞 | |
| CVE-2023-37742 | WebBoss.io 跨站脚本漏洞 | |
| CVE-2023-36339 | WebBoss.io 安全漏洞 | |
| CVE-2021-35391 | Deskpro 代码问题漏洞 |
No comments yet