Description
This module exploits a vulnerability present in all versions of Telpho10 telephone system appliance. This module generates a configuration backup of Telpho10, downloads the file and dumps the credentials for admin login, phpmyadmin, phpldapadmin, etc. This module has been successfully tested on the appliance versions 2.6.31 and 2.6.39.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/admin/http/telpho10/credential_dumpmsf undefined(credential_dump) > show actions ...actions...msf undefined(credential_dump) > set ACTION < action-name >msf undefined(credential_dump) > show options ...show and set options...msf undefined(credential_dump) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub