Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:42:04 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2169782736&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0912-exploits%2Fcorehttp_cgienabled.rb.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2169782736.1338187324.1338187324.1338187324.1%3B%2B__utmz%3D32867617.1338187324.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) CoreHTTP 0.5.3.1 Command Execution http://packetstormsecurity.org/files/84212/corehttp_cgienabled.rb.txt http://packetstormsecurity.org/files/84212/corehttp_cgienabled.rb.txt http://packetstormsecurity.org/files/84212/CoreHTTP-0.5.3.1-Command-Execution.html Wed, 23 Dec 2009 16:52:38 GMT This Metasploit module exploits a remote command execution vulnerability in corehttp versions 0.5.3.1 and earlier. It requires that you know the name of a cgi file on the server. NOTE: If you want to do something more than remote shell, you'll have to change CGICMD.