This Metasploit module utilizes the Net-NTLMv2 reflection between DCOM/RPC to achieve a SYSTEM handle for elevation of privilege. Currently the module does not spawn as SYSTEM, however once achieving a shell, one can easily use incognito to impersonate the token.
10aca5238c09e9bf6cc039620feb2267cc144082ac9a5d8868637ad860f00b93
This Metasploit module exploits a vulnerability in the eval command present in Xdebug versions 2.5.5 and below. This allows the attacker to execute arbitrary php code as the context of the web user.
a94a19cfaf669742a83aa9ced9e5f3db211d2e4e73a6dab97341c79d196c8536
This Metasploit module generates an DDE command to place within a word document, that when executed, will retrieve a HTA payload via HTTP from an web server.
c78e1c6fecbebe56444e1bea5963cf977f091c6e851633f4e7b05b3de8fff37b
Within Polycom command shell, a command execution flaw exists in lan traceroute, one of the dev commands, which allows for an attacker to execute arbitrary payloads with telnet or openssl.
3b279dce0d9c718461f40aa25c45dc95b868af836e0345f39644d63fbbe6acdf
This Metasploit module exploits a flaw in how the Equation Editor handles OLE objects in memory to execute arbitrary code using RTF files without interaction.
16ad4379e6651e3ce0e9433a9c32d2a5e70809affcfd3f999c329227ce6dbc46
This Metasploit module leverages an unauthenticated credential disclosure vulnerability to execute arbitrary commands on DIR-850L routers as an authenticated user.
cc7df6cd9e0b41f07f8a1a231bb9a9254b142b689a4c11057c1e7752ab535833