module

Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE

Disclosed
Jul 6, 2022

Description

This module exploits an unauthenticated command injection vulnerability in Roxy-WI
prior to version 6.1.1.0. Successful exploitation results in remote code execution
under the context of the web server user.

Roxy-WI is an interface for managing HAProxy, Nginx and Keepalived servers.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.