PHP < 5.3.12 / < 5.4.2 - CGI Argument Injection
Last updated
Last updated
Try to browse
http://10.2.20.205/phpinfo.php
Manual/Script Exploitation
Find an exploit
Modify pwn_code
variable and insert PHP reverse shell code
Unprivileged access with "www-data" user
Automatic MSF exploit/multi/http/php_cgi_arg_injection
module can be used too.
exploit/multi/http/php_cgi_arg_injection