HTB Writeup – Alert
Posted on 2024-11-25
Classic XSS + LFI exploit combination
Deserialization for pymatgen & Directory Traversal on aiohttp
LFI, JWT Forgery, SQLi, Crontab abuse, Mercurial hook, Rsync privesc
XSS + RCE for PrestaShop & exploit SSTI on ChangeDetection.io
Exploit H2 Database for Java web app & abuse Apache Thrift
SQLPad RCE vulnerability & Froxlor exploit via Chrome remote debugging
RCE for CACTI monitor system, Auth bypass for Duplicati backup solution.
Skipper Proxy SSRF, Blazor traffic exploit, Privesc from process monitor
CVE-2023-41425 for WonderCMS RCE with malicious themes module.