pentestTeam[verified]@TeamPentestGeneral
The post highlights an AI assistant for automated ethical hacking exercises, mentioning Ghostcat (CVE‑2020‑1938) but providing no PoC, exploit details, active exploitation evidence, patches, or technical depth.
AkatsukiLegion@_AkatsukiLegionExploit
The text references a Python PoC for CVE‑2020‑1938 and indicates that attackers used it in a targeted intrusion that involved internal network mapping.
tin3r@tin3r_Exploit
The post announces a Lathack writeup on Ghostcat (CVE‑2020‑1938) in Apache Tomcat, outlining steps like a WAR‑based reverse shell, but it does not present explicit exploit code or evidence of active exploitation.
Thinkkun@think_kunGeneral
The tweet highlights that Tomcat 9.0.31 is associated with CVE-2020-1938 and encourages using nmap for version detection but offers no further technical detail or actionable information.
49@MDPorschExploit
The post documents a successful exploitation of Ghostcat (CVE-2020-1938) on Metasploitable 2 using Metasploit, confirming the vulnerability's exploitability in a lab environment.
Havij@_havijExploit
The post announces a root-level exploit for CVE‑2020‑1938 via an AJP misconfiguration, linking to a resource that likely contains the PoC, but it does not provide code, indicate active exploitation, or mention a patch.