
Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2
Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2
Working exploit for Open Web Analytics 1.7.3 - RCE enhenced with pentestmonkey's php reverse shell, Fixed issue of not able to find user in cache.
Original soruce exploit can be found on here
Add your attacker machine's IP and PORT in php-reverse-shell.php file and run the exploit.py with argument -u for vulnerable target url.
python3 exploit.py -u https://target.host/owa/
@JacobEbben
@pentestmonkey