nmap
Port 8500 – ColdFusion
ColdFusion File Inclusion
https://www.exploit-db.com/exploits/14641
Hash Crack
JSP Shell Creation & File Upload & Shell
Run the task and open the file on the following directory
C:\ColdFusion8\wwwroot\CFIDE\shell.jsp
Privilege escalation
Python exploit suggester
Upload ms10-059.exe (Chimchurri) via Powershell
Get an admin shell with exe file
.