Description
This module exploits a command injection vulnerability in the SAPHostControl Service, by sending a specially crafted SOAP request to the management console.
In order to deal with the spaces and length limitations, a WebDAV service is created to run an arbitrary payload when accessed as a UNC path. Because of this, the target host must have the WebClient service (WebDAV Mini-Redirector) enabled. It is enabled and automatically started by default on Windows XP SP3, but disabled by default on Windows 2003 SP2.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/windows/http/sap/host_control_cmd_execmsf undefined(host_control_cmd_exec) > show actions ...actions...msf undefined(host_control_cmd_exec) > set ACTION < action-name >msf undefined(host_control_cmd_exec) > show options ...show and set options...msf undefined(host_control_cmd_exec) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub