Advantech Switch Bash Environment Variable Code Injection

Discussion in 'News Aggregator' started by Packet Storm, 2 Dec 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This Metasploit module targets the 'ping.sh' CGI script, accessible through the Boa web server on Advantech switches. This Metasploit module was tested against firmware version 1322_D1.98.

    Continue reading...
     

Share This Page

Loading...