Exploit catalog results

Showing 16 PoCs on this page

Metasploit

Marvell QConvergeConsole Path Traversal (CVE-2025-6793)

Metasploit auxiliary PoCby Michael HeinzlAdded to Metasploit 2026-04-16
ExploitCVE-2025-67931 file

auxiliary_gather/qconvergeconsole_traversal · Ruby

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

Metasploit auxiliary module that exploits CVE-2025-6793, a path traversal vulnerability in Marvell QConvergeConsole, to retrieve and delete arbitrary files from the target system without authentication.

Backdoor review

No backdoor observed in reviewed code

The module is a standard Metasploit auxiliary module that exploits CVE-2025-6793, a path traversal vulnerability in Marvell QConvergeConsole. It reads and deletes a specified file from the target. No backdoor, deceptive payload, or concealed operator-directed harm is present. The module includes a DefangedMode safety check and uses only documented Metasploit APIs for HTTP requests, file storage, and reporting.

ClassificationExploit
Model confidence95%
AuthenticationNot required
Languagesruby
Target softwareMarvell QConvergeConsole
Attack typespath traversalinformation disclosurearbitrary file deletion
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The module actively sends crafted HTTP requests to exploit a path traversal vulnerability, retrieves file contents, and stores them as loot. This constitutes exploitation, not just scanning or detection.

modules/auxiliary/gather/qconvergeconsole_traversal.rb:102-146

Requirements

  • Target must be running Marvell QConvergeConsole <= v5.5.0.85 with the vulnerable QLogicDownloadServlet endpoint accessible.modules/auxiliary/gather/qconvergeconsole_traversal.rb:17-18

Observed behavior

  • Sends an HTTP GET request to the QLogicDownloadServlet endpoint with user-controlled folder and file parameters to read an arbitrary file from the target system.modules/auxiliary/gather/qconvergeconsole_traversal.rb:114-128
  • Stores the retrieved file content as loot in the Metasploit database.modules/auxiliary/gather/qconvergeconsole_traversal.rb:136
  • The file retrieval operation also deletes the file from the remote server as a side effect.modules/auxiliary/gather/qconvergeconsole_traversal.rb:18
  • Includes a check method that fingerprints the target version by extracting a GWT strong name and version string from JavaScript files.modules/auxiliary/gather/qconvergeconsole_traversal.rb:56-100
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Safety Mechanism
Payload withheldDemonstrates the module author's intent to warn operators about the destructive file deletion side effect, consistent with legitimate security tooling.modules/auxiliary/gather/qconvergeconsole_traversal.rb:51modules/auxiliary/gather/qconvergeconsole_traversal.rb:103-113
Destructive Behavior Disclosure
Payload withheldThe file deletion is a known side effect of the vulnerability, not a hidden backdoor. The module transparently discloses this behavior.modules/auxiliary/gather/qconvergeconsole_traversal.rb:17-18modules/auxiliary/gather/qconvergeconsole_traversal.rb:105-107
Review boundaries

What the analysis did not establish

  • Only the module source code and metadata are provided; Metasploit framework mixins, libraries, and external payloads are not expanded.
  • The evidence does not include runtime execution output or confirmation that the exploit works against a live target.
  • Only the module source and metadata are reviewed; Metasploit framework mixins (HttpClient, AutoCheck, Report) and libraries are not expanded, but the module's use of them is standard and non-suspicious.
  • Binary files are flagged as metadata-only and not analyzed, but no binary files are included in the evidence.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

Metasploit

LG Simple Editor Command Injection (CVE-2023-40504)

Metasploit exploitby Michael HeinzlAdded to Metasploit 2024-08-07
Not analyzedCVE-2023-405041 file

exploit_windows/http/lg_simple_editor_rce_uploadvideo · Ruby

Metasploit

LG Simple Editor Remote Code Execution

Metasploit exploitby Ege Balcı <egebalci@pm.me>Added to Metasploit 2023-08-29
Not analyzedCVE-2023-404981 file

exploit_windows/http/lg_simple_editor_rce · Ruby

Metasploit

Advantech iView NetworkServlet Command Injection

Metasploit exploitby Shelby Pace, plus 1 additional contributorAdded to Metasploit 2022-07-19
Not analyzedCVE-2022-21431 file

exploit_windows/http/advantech_iview_networkservlet_cmd_inject · Ruby

Metasploit

Advantech WebAccess Dashboard Viewer uploadImageCommon Arbitrary File Upload

Metasploit exploitby Zhou Yu <504137480@qq.com>, plus 1 additional contributorAdded to Metasploit 2016-04-17
Not analyzedCVE-2016-08541 file

exploit_windows/scada/advantech_webaccess_dashboard_file_upload · Ruby

Metasploit

Solarwinds Firewall Security Manager 6.6.5 Client Session Handling Vulnerability

Metasploit exploitby mr_me <steventhomasseeley@gmail.com>, plus 1 additional contributorAdded to Metasploit 2015-03-31
Not analyzedCVE-2015-22841 file

exploit_windows/http/solarwinds_fsm_userlogin · Ruby

Metasploit

NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2012-11-20
Not analyzedCVE-2012-59321 file

exploit_windows/novell/netiq_pum_eval · Ruby

Metasploit

Cisco Linksys PlayerPT ActiveX Control Buffer Overflow

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2012-07-26
Not analyzedCVE-2012-02841 file

exploit_windows/browser/cisco_playerpt_setsource · Ruby

Metasploit

AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution

Metasploit exploitby juan vazquez <juan.vazquez@metasploit.com>Added to Metasploit 2012-07-09
Not analyzedCVE-2011-26571 file

exploit_windows/browser/zenworks_helplauncher_exec · Ruby

Metasploit

Tom Sawyer Software GET Extension Factory Remote Code Execution

Metasploit exploitby Elazar Broad, plus 1 additional contributorAdded to Metasploit 2012-06-08
Not analyzedCVE-2011-22171 file

exploit_windows/browser/tom_sawyer_tsgetx71ex552 · Ruby

Metasploit

McAfee Virtual Technician MVTControl 6.3.0.1911 GetObject Vulnerability

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-04-30
Not analyzedCVE-2012-45981 file

exploit_windows/browser/mcafee_mvt_exec · Ruby

Metasploit

TRENDnet SecurView Internet Camera UltraMJCam OpenFileDlg Buffer Overflow

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-04-06
Not analyzedCVE-2012-48761 file

exploit_windows/browser/ultramjcam_openfiledig_bof · Ruby

Metasploit

Dell Webcam CrazyTalk ActiveX BackImage Vulnerability

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-03-20
Not analyzedUnlinked1 file

exploit_windows/browser/dell_webcam_crazytalk · Ruby

Metasploit

McAfee SaaS MyCioScan ShowReport Remote Command Execution

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2012-01-17
Not analyzedUnlinked1 file

exploit_windows/fileformat/mcafee_showreport_exec · Ruby

Metasploit

CA Arcserve D2D GWT RPC Credential Information Disclosure

Metasploit exploitby bannedit <bannedit@metasploit.com>Added to Metasploit 2011-08-01
Not analyzedCVE-2011-30111 file

exploit_windows/http/ca_arcserve_rpc_authbypass · Ruby

Metasploit

Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

Metasploit exploitby sinn3r <sinn3r@metasploit.com>Added to Metasploit 2011-04-08
Not analyzedCVE-2011-100281 file

exploit_windows/browser/real_arcade_installerdlg · Ruby