Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2026-72898-safe-detection — Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase) | Kitploit
ツール/GitHubGitHub/franc-zar/cve-2026-72898-safe-detection
Vulnerability ScannersVulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration Testing
GitHubfranc-zar/cve-2026-72898-safe-detection

CVE-2026-72898-safe-detection

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

リポジトリを見る
21日前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
要求された言語のコンテンツは利用できません。英語版を表示しています。

CVE-2026-72898-safe-detection

Simple script to achieve safe and non-destructive active detection of CVE-2026-72898 (SQLi in Metabase)

It attempts to determine if a Metabase instance is vulnerable to the SQL injection vulnerability in the password reset endpoint. The script is designed to be safe and not cause any harm to the target system. It does not attempt to exploit the vulnerability by changing any data or performing any destructive actions. The script sends a series of sleep or delay payloads to the target Metabase instance to determine if the SQL injection is possible and measures the response times accordingly. It supports multiple database types and can perform a brute-force scan to test all supported database types if the user is unsure of the target's database type.

Usage:

root@kitploit:~
cve_2026_72898_scanner.py - A script to safely scan for CVE-2026-72898.

options:
  -h, --help            show this help message and exit
  --host HOST           Target Metabase host
  --port PORT           Target Metabase port
  --schema {http,https}
                        Target Metabase schema
  --db-type {mysql,postgres,mariadb}
                        Target Metabase application SQL database type
  --brute               Enable brute force mode (try all database types) - avoid as possible, as it may trigger rate limiting on the target system after around 10 requests with later exponential backoff on retry

Legal Disclaimer

This tool is strictly for educational purposes and authorized security testing. Do not use it against systems without explicit written permission from the owner.

The author assumes no liability and is not responsible for any misuse, damage, data loss, or legal consequences caused by this program. Use entirely at your own risk.

ツールをダウンロード