xsspresso
xsspresso
Tags/ File Upload

File Upload

12 writeups tagged with File Upload

WebEasyWindows

VHL — WinAS01

XAMPP 1.8.1 on Windows with Apache and SSL. Exploited outdated XAMPP configuration and weak credentials for web shell upload.

#XAMPP#Apache#Web Shell
Feb 13, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Jennifer

Windows with FileZilla FTP and CMS Mini web app. FTP credential exposure and CMS RCE via file upload for initial foothold.

#FileZilla#FTP#CMS
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Records

OpenEMR medical records application. Exploited a pre-auth SQL injection CVE and file upload for shell access.

#OpenEMR#SQLi#File Upload
Feb 11, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Helpdesk

FTP with anonymous access reveals helpdesk application credentials. SQL injection and file upload lead to remote code execution.

#FTP#SQLi#File Upload
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Web01-Dev

Development web server with FTP credentials leaked via anonymous login. Credential reuse and web shell upload for root.

#FTP#Web Shell#File Upload
Feb 8, 2025Virtual Hacking Labs
WebEasyLinux

HTB — Help

HelpDeskZ GraphQL unauthenticated query exposes user creds. File upload bypass for PHP webshell. Kernel 4.4 exploit for root privilege escalation.

#GraphQL#File Upload#Kernel Exploit
Jan 20, 2025HackTheBox
WebEasyWindows

HTB — Love

SSRF on a voting system bypasses firewall to reach internal file analysis service. PHP file upload for RCE, AlwaysInstallElevated for SYSTEM.

#SSRF#File Upload#AlwaysInstallElevated
Jan 16, 2025HackTheBox
WebEasyLinux

HTB — Usage

Laravel admin panel SQL injection via search parameter. Malicious PNG for RCE via file upload. Wildcard file read on sudo binary for root flag.

#SQLi#Laravel#File Upload
Jan 15, 2025HackTheBox
WebEasyWindows

HTB — Buff

Gym Management Software RCE via unauthenticated file upload. CloudMe buffer overflow with port forwarding for privilege escalation.

#File Upload#RCE#Buffer Overflow
Jan 15, 2025HackTheBox
WebEasyWindows

HTB — Artic

ColdFusion 8 arbitrary file upload RCE (CVE-2009-2265). MS10-059 (Chimichurri) token impersonation for privilege escalation.

#ColdFusion#CVE-2009-2265#File Upload
May 30, 2022HackTheBox
WebEasyLinux

HTB — Networked

PHP file upload bypass with double extension and MIME spoofing. Cron-executed user script for lateral move, ifcfg privesc to root.

#File Upload#PHP#Cron
Apr 26, 2022HackTheBox
WebEasyLinux

HTB — Nibbles

Nibbleblog CMS with guessable admin credentials leads to arbitrary PHP file upload and remote code execution.

#Nibbleblog#File Upload#RCE
Mar 25, 2022HackTheBox