HTB Writeup – Browsed
Posted on 2026-01-11
Chrome extension JavaScript injection & Python .pyc poisoning
Chrome extension JavaScript injection & Python .pyc poisoning
There is no excerpt because this is a protected post.
CVE-2025-24367 (Cacti Auth RCE), CVE-2025-9074 (Docker Desktop Escape)
SQL injection abusing PDO substitution in PHP Prepared Statement
There is no excerpt because this is a protected post.
BadSuccessor attack by creating a malicious dMSA object in AD
There is no excerpt because this is a protected post.
Transform XSLT to HTML with extensions → special XML “SSTI”
There is no excerpt because this is a protected post.