HTB Writeup – Editor
Posted on 2025-08-03
XWiki RCE (CVE 2025‑24893) & NetDATA Path Hijacking (CVE-2024-32019)
XWiki RCE (CVE 2025‑24893) & NetDATA Path Hijacking (CVE-2024-32019)
RCE for Roundcube (CVE‑2025‑49113) & below Privesc (CVE-2025-27591)
CVE-2024-52301 to alter Laravel environment and Linux ENV injection
Exploit GoPhish Webhook using n8n, and the Restic Backup Utility
APOC Reversing and Cypher Injection with Java-based application
From NTLM to Kerberos Relaying Attack, Spoofing UPNs to privesc
Exploit open-source C2s: Havoc (CVE-2024-41570) & Hardhat
Exploit Ghost CMS 5.58.0 CVE-2023-40028 after a Git leak
Zabbix CVE-2024-36467 (JSON RPC IDOR) & CVE-2024-42327 (SQLi)