CVE-2023-38646 Metabase RCE Tool
Verification Module
- Input the specified URL to detect unauthorized token

Command Execution
- This module requires executing the verification module to obtain a token first
- JarLocation: the location of metabase.jar, default is current directory

Memory Shell Injection
- Currently only cmd and godzilla modes are implemented, controlled via x-client-data
- x-client-data:cmd – write command in the cmd request header
- x-client-data:godzilla – directly connect to Godzilla, default password is pass

