This is the fourth in a series of demos I am creating about Remote Command Injection vulnerabilities for my paper on them.
This demos HTTP POST injections by using GWEE (Generic Web Exploitation Engine) to inject a vulnerable POST parameter in a buggy web app. It launches a reverse shell and gives us a terminal session on the owned box.
This is similar to the GET injection demo, but using POST this time...
Check out our whitepaper on this HERE: http://insecurety.net/papers/web-apps...