ajp-ghostcat
Exploit Apache JServ Protocol (AJP) misconfigurations and Ghostcat (CVE-2020-1938) for file read and remote code execution on Apache Tomcat. Use when port 8009 is open or AJP connector is exposed.
Also installable via skills CLI
npx skills add blacklanternsecurity/red-run/skills/web/ajp-ghostcat