Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
MetabaseRceTools — CVE-2023-38646 Metabase RCE | Kitploit
Tools/GitHubGitHub/boogipop/metabasercetools
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubboogipop/metabasercetools

MetabaseRceTools

CVE-2023-38646 Metabase RCE

View Repository
54522 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

MetabaseRceTools

CVE-2023-38646 Metabase RCE Tool

CVE-2023-38646 RCE Graphical Exploitation Tool

Verification Module

  • Input the specified URL to detect unauthorized token

image-20231011112444404

Command Execution

  • This module requires executing the verification module to obtain a token first
  • JarLocation: the location of metabase.jar, default is current directory

image-20231011112525296

Memory Shell Injection

  • Currently only cmd and godzilla modes are implemented, controlled via x-client-data
  • x-client-data:cmd – write command in the cmd request header
  • x-client-data:godzilla – directly connect to Godzilla, default password is pass

image-20231011112542389

image-20231011112958066

Download Tool