xsspresso
xsspresso
Tags/ Actuator

Actuator

1 writeup tagged with Actuator

WebEasyLinux

HTB — CozyHosting

Spring Boot Actuator exposes session cookies. Hijacked admin session to exploit command injection in SSH endpoint for reverse shell.

#Spring Boot#Actuator#Command Injection
Nov 26, 2024HackTheBox