Enumeration
Nmap
The machine has two apache and one of them has a vulnerable version 2.4.49
Fuzzing port 8080
This vulnerable depends of cgi-bin folder, let’s fuzzing to see if this machine has this folder
Yes, the machine has the folder.
Exploit
CVE-2021-41773
Reverse shell
- Open a listener port and create a reverse shell
Root
Bypass Python sandboxes