HTTP
Last updated
search xoda
use exploit/unix/webapp/xoda_file_upload
info
# Description:
# This module exploits a file upload vulnerability found in XODA
# 0.4.5. Attackers can abuse the "upload" command in order to upload a
# malicious PHP file without any authentication, which results in
# arbitrary code execution. The module has been tested successfully on
# XODA 0.4.5 and Ubuntu 10.04.
set TARGETURI /
run