CGI
Theory
Practice
#Linux
feroxbuster -u http://<TARGET> -w /usr/share/SecList/Discovery/Web-Content/CGIs.txt
#Windows
feroxbuster -u http://<TARGET> -w /usr/share/SecList/Discovery/Web-Content/CGI-Microsoft.fuzz.txt
nikto -h <TARGET> -C allVulnerabilities
ShellShock - CVE-2014-6271
Proxy (MitM to Web server requests)
CGI RCE - CVE-2012-1823, CVE-2012-2311
Resources
Last updated