xsspresso
xsspresso
Tags/ ImageMagick

ImageMagick

3 writeups tagged with ImageMagick

WebMediumLinux

HTB — Imagery

ImageMagick policy bypass enables SSRF and local file read to steal credentials. Sudo misconfiguration grants root access.

#ImageMagick#SSRF#File Read
Oct 4, 2025HackTheBox
WebEasyLinux

HTB — Titanic

Flask app path traversal via download endpoint reads arbitrary files including admin credentials. Magick ImageMagick CVE-2024-41817 for root shell.

#Path Traversal#Flask#ImageMagick
Feb 16, 2025HackTheBox
MiscEasyLinux

HTB — Pilgrimage

ImageMagick CVE-2022-44268 arbitrary file read via malicious PNG. SQLite database exposes credentials. Binwalk CVE-2022-4510 for root shell.

#ImageMagick#CVE-2022-44268#Binwalk
Nov 26, 2024HackTheBox