This Metasploit module exploits a command injection in Apache Continuum versions 1.4.2 and below. By injecting a command into the installation.varValue POST parameter to /continuum/saveInstallation.action, a shell can be spawned.
cf845d6fbc3b09514ed47ba1ed811ff6c6d343b0941a626f3ff4522492ad83c7
Apache Continuum version 1.4.2 suffers from command injection and cross site scripting vulnerabilities.
33753b859896ef529d7220d4783017ba4819ff23e9203b674af3f8b5ff78b5f1