xsspresso
xsspresso
Tags/ PHP

PHP

4 writeups tagged with PHP

WebMediumLinux

VHL — PMV02

b2evolution blog CMS on Ubuntu. Authenticated file manager abuse and PHP filter injection lead to remote code execution.

#b2evolution#File Manager#PHP
Feb 17, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Fed

Custom PHP forum on Fedora Linux with MariaDB. SQL injection bypasses authentication, leading to file write and shell upload.

#PHP#SQLi#MariaDB
Feb 12, 2025Virtual Hacking Labs
MiscEasyLinux

VHL — Natural

FTP anonymous login exposes web application files. Abused file write via FTP to upload a PHP webshell for initial access.

#FTP#Anonymous Login#Web Shell
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

HTB — Networked

PHP file upload bypass with double extension and MIME spoofing. Cron-executed user script for lateral move, ifcfg privesc to root.

#File Upload#PHP#Cron
Apr 26, 2022HackTheBox