This Metasploit module exploits an authenticated directory traversal vulnerability in WordPress Plugin "NextGEN Gallery" version 2.1.7, allowing to read arbitrary directories with the web server privileges.
2c0cd7aee77fbdb8a99fcc09f39bd549ae4823975d07eaa06182ce30e5d70738
47 bytes small Linux/x86_64 polymorphic execve-stack shellcode.
83cd639a392721f34f27d28e87d3aa36ceba9b8a58c07d37c78e1669a41134f7
122 bytes small Linux/x64 TCP reverse shell with password. Polymorphic version.
e8424d124c151ace53fdcbf7276880cb684cf019d4f630594c5daae15d6852d4
Linux x86_64 xor/not/div encoded execve shellcode.
e04b7503ac24cbbcbcba03ec95f7abb04b2fe4103b59c7107226d057aaab2b01
Netgear router version 1.0.0.24 with JNR1010 firmware suffers from improper session management and bypass vulnerabilities.
e490b8e5eaf82cdabe3b918f772a70f63831a13c6260c4a3f649b5a052eb2bbf
Netgear router version 1.0.0.24 with JNR1010 firmware suffers from a cross site request forgery vulnerability.
da6530ed94ec74ddcb325b48d68b02ef2fe16d9c6ec393e137a00d4987f9e68a
18 bytes small Linux/x86_64 egghunting shellcode.
4be4948b091b9dfa6f038690c14c3670b190b01405203192db73c45d19c48cd5
151 bytes small TCP reverse shell with password prompt shellcode.
d8c504e589fd31d7ee0a0eb6d9fd5e95361c2c7780febf4c0b2c76505b3586bd
162 bytes small TCP bindshell with password prompt shellcode.
245daf74cf5198905ae2efee0c271aa0cf400d6d214089d86fe3c11b17a58110