xsspresso
xsspresso
Tags/ Deserialization

Deserialization

3 writeups tagged with Deserialization

WebMediumLinux

HTB — Expressway

Express.js prototype pollution vulnerability leads to remote code execution via deserialization of a crafted payload.

#Prototype Pollution#Node.js#Deserialization
Sep 27, 2025HackTheBox
WebMediumWindows

VHL — Trace

IIS 10.0 running Kartris eCommerce on Windows. SQL injection and .NET deserialization chain leads to code execution and privilege escalation.

#IIS#Kartris#SQLi
Feb 15, 2025Virtual Hacking Labs
WebEasyLinux

HTB — Broker

Apache ActiveMQ CVE-2023-46604 unauthenticated RCE via ClassInfo deserialization. Sudo nginx misconfiguration for arbitrary file read and root access.

#ActiveMQ#CVE-2023-46604#Deserialization
Jan 18, 2025HackTheBox