module
Generic HTTP Command Execution
| Disclosed | Created |
|---|---|
| Feb 26, 2026 | Mar 27, 2026 |
Disclosed
Feb 26, 2026
Created
Mar 27, 2026
Description
This module interacts with existing command execution functionality on a target system,
where user-supplied input is directly passed to system execution functions via a HTTP request.
This could be from an existing vulnerability, or uploaded webshells such as:
It is likely that HTTP evasion options will break this exploit.
where user-supplied input is directly passed to system execution functions via a HTTP request.
This could be from an existing vulnerability, or uploaded webshells such as:
It is likely that HTTP evasion options will break this exploit.
Authors
egypt [email protected]
g0tmi1k
g0tmi1k
Platform
Linux,OSX,Unix,Windows
Architectures
cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.