Tomcat CGI
Enumeration
Using NMAP
$ nmap -p- -sC -Pn 10.129.204.227 --open
8080/tcp open http-proxy
|_http-title: Apache Tomcat/9.0.17
|_http-favicon: Apache TomcatFuzzing .bat and .cgi
$ ffuf -w /usr/share/dirb/wordlists/common.txt -u http://10.129.204.227:8080/cgi/FUZZ.cmd
$ ffuf -w /usr/share/dirb/wordlists/common.txt -u http://10.129.204.227:8080/cgi/FUZZ.batExploitation
CVE-2019-0232
Notes
Important Vulnerabilities
Last updated