module
DenyAll Web Application Firewall Remote Code Execution
Disclosed | Created |
---|---|
2017-09-19 | 2018-05-30 |
Disclosed
2017-09-19
Created
2018-05-30
Description
This module exploits the command injection vulnerability of DenyAll Web Application Firewall. Unauthenticated users can execute a
terminal command under the context of the web server user.
terminal command under the context of the web server user.
Author
Mehmet Ince mehmet@mehmetince.net
Platform
Python
Architectures
python
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.