Description
This module exploits a path traversal vulnerability in the "linuxpkgs" action of "agent" controller of the Red Hat CloudForms Management Engine 5.1 (ManageIQ Enterprise Virtualization Manager 5.0 and earlier). It uploads a fake controller to the controllers directory of the Rails application with the encoded payload as an action and sends a request to this action to execute the payload. Optionally, it can also upload a routing file containing a route to the action. (Which is not necessary, since the application already contains a general default route.)
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/cfme_manageiq_evm_upload_execmsf undefined(cfme_manageiq_evm_upload_exec) > show actions ...actions...msf undefined(cfme_manageiq_evm_upload_exec) > set ACTION < action-name >msf undefined(cfme_manageiq_evm_upload_exec) > show options ...show and set options...msf undefined(cfme_manageiq_evm_upload_exec) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub