HTB Writeup – Gavel
Posted on 2025-11-30
SQL injection abusing PDO substitution in PHP Prepared Statement
SQL injection abusing PDO substitution in PHP Prepared Statement
There is no excerpt because this is a protected post.
Transform XSLT to HTML with extensions → special XML “SSTI”
Exploit IKE IPSec via UDP discovery & the SUDO binex privesc
Python SSTI and Django Cache poisoning with Pickle Deserialization
CrushFTP auth bypass (CVE-2025-31161) and Erlang shell manipulation
Next.js auth bypass (CVE-2025-29927) & Hashicorp Terraform abusing