module

NETGEAR ProSafe Network Management System 300 Authenticated File Download

Disclosed
2016-02-04
Created
2018-05-30

Description

Netgear's ProSafe NMS300 is a network management utility that runs on Windows systems.
The application has a file download vulnerability that can be exploited by an
authenticated remote attacker to download any file in the system.
This module has been tested with versions 1.5.0.2, 1.4.0.17 and 1.1.0.13.

Author

Pedro Ribeiro pedrib@gmail.com

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/admin/http/netgear_auth_download
msf auxiliary(netgear_auth_download) > show actions
...actions...
msf auxiliary(netgear_auth_download) > set ACTION < action-name >
msf auxiliary(netgear_auth_download) > show options
...show and set options...
msf auxiliary(netgear_auth_download) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.