Advantech Switch Bash Environment Variable Code Injection
Posted by deepcore on December 2, 2015 – 7:01 pm
This Metasploit module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This Metasploit module targets the ‘ping.sh’ CGI script, accessible through the Boa web server on Advantech switches. This Metasploit module was tested against firmware version 1322_D1.98.
Post a reply
You must be logged in to post a comment.