module

Sophos Web Protection Appliance patience.cgi Directory Traversal

Disclosed
Apr 3, 2013
Created
May 30, 2018

Description

This module abuses a directory traversal in Sophos Web Protection Appliance, specifically
on the /cgi-bin/patience.cgi component. This module has been tested successfully on the
Sophos Web Virtual Appliance v3.7.0.

Authors

Wolfgang Ettlingers
juan vazquez juan.vazquez@metasploit.com

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/admin/http/sophos_wpa_traversal
msf auxiliary(sophos_wpa_traversal) > show actions
...actions...
msf auxiliary(sophos_wpa_traversal) > set ACTION < action-name >
msf auxiliary(sophos_wpa_traversal) > show options
...show and set options...
msf auxiliary(sophos_wpa_traversal) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.