Nostromo 1.9.6 Directory Traversal / Remote Command Execution

This Metasploit module exploits a remote command execution vulnerability in Nostromo versions 1.9.6 and below. This issue is caused by a directory traversal in the function http_verify in nostromo nhttpd allowing an attacker to achieve remote code execution via a crafted HTTP request.

[remote] Nostromo – Directory Traversal Remote Command Execution (Metasploit)

Nostromo – Directory Traversal Remote Command Execution (Metasploit)

[webapps] ownCloud 10.3.0 stable – Cross-Site Request Forgery

ownCloud 10.3.0 stable – Cross-Site Request Forgery

[local] OpenVPN Private Tunnel 2.8.4 – 'ovpnagent' Unquoted Service Path

OpenVPN Private Tunnel 2.8.4 – ‘ovpnagent’ Unquoted Service Path

[webapps] TheJshen contentManagementSystem 1.04 – 'id' SQL Injection

TheJshen contentManagementSystem 1.04 – ‘id’ SQL Injection

[webapps] Apache Solr 8.2.0 – Remote Code Execution

Apache Solr 8.2.0 – Remote Code Execution