This demo shows how we can exploit the infamous PHP-CGI Arguement Injection vulnerability in a number of ways. Using the commandline tool "POST" from lwp-requests, using a custom written Python exploit I wrote, or by simply using Metasploit.
Music in the demo is by Blackmail House - soundcloud.com/blackmail-house and is used with permission, under the "I buy the band members a case of beer" licence.
The article and exploit code may be found at http://insecurety.net/?p=705