[feature request] Apache Tomcat/JBoss EJBInvokerServlet
thsle3p opened this issue · 2 comments
thsle3p commented
Can a module be added to implement this invoker for jboss http://www.exploit-db.com/exploits/28713/? Some sys admins restrict /invoker/JMXInvokerServlet/ but not /invoker/EJBInvokerServlet/ so it would be good to have a module to exploit that.
hatRiot commented
I was under the impression that removing the JMXInvokerServlet was essentially the same as removing the EJBInvokerServlet.
Thanks for opening this issue; I'll get it knocked out. Leaving this open until the commit comes through.
hatRiot commented
A deployer for EJBInvokerServlet now in dev; should be available in trunk in the next merge.