17. Attacking Tomcat CGI
1. Vulnerability Overview
CVE-2019-0232 - Remote Code Execution (RCE)
2. Enumeration
Nmap Scan
nmap -p- -sC -Pn 10.129.204.227 --openCGI Script Discovery (ffuf)
3. Exploitation
Basic Command Injection
Retrieve Environment Variables
Hardcoded Path Execution (whoami)
URL Encoding Bypass
4. Key Considerations
5. Commands Summary
Last updated