
Python exploit script for CVE-2018-1306 in Apache Pluto 3.0.0, enabling malicious file upload via HTTP method tampering to achieve remote code execution.
Apache Pluto 3.0.0 issue in the authorisation logic which lets attacker upload malicious files by tampering HTTP methods.
Script written in python3.
Usage: python3 ./plutorce.py http://192.168.0.1/ webshell.jsp