xsspresso
xsspresso
Tags/ File Read

File Read

4 writeups tagged with File Read

WebMediumLinux

HTB — Imagery

ImageMagick policy bypass enables SSRF and local file read to steal credentials. Sudo misconfiguration grants root access.

#ImageMagick#SSRF#File Read
Oct 4, 2025HackTheBox
WebEasyLinux

HTB — Alert

Markdown XSS for stored cross-site scripting. SSRF via file:// to leak local web app source code, exposed internal site with writable path for root.

#XSS#SSRF#Markdown
Jan 10, 2025HackTheBox
WebEasyLinux

HTB — LinkVortex

Ghost CMS CVE-2023-40028 arbitrary file read vulnerability. Symlink traversal via config reveals credentials for lateral movement and sudo privesc.

#Ghost CMS#CVE-2023-40028#Symlink
Jan 8, 2025HackTheBox
MiscMediumLinux

HTB — Solidstate

Apache James 2.3.2 arbitrary file read leaks user creds. Root via world-writable cron script executed by root.

#SMTP#James#File Read
Apr 2, 2022HackTheBox