xsspresso
xsspresso
Tags/ Path Traversal

Path Traversal

5 writeups tagged with Path Traversal

WebEasyLinux

HTB — Nocturnal

ISP file manager path traversal leaks app config with credentials. ISPConfig adduser API abuse leads to root.

#Path Traversal#ISPConfig#Config Disclosure
May 24, 2025HackTheBox
WebEasyLinux

HTB — Code

Python code sandbox escape via restricted eval bypass reads SSH keys. Root via path traversal in the backy backup tool.

#Python#Sandbox Escape#eval
Mar 29, 2025HackTheBox
WebEasyLinux

HTB — Titanic

Flask app path traversal via download endpoint reads arbitrary files including admin credentials. Magick ImageMagick CVE-2024-41817 for root shell.

#Path Traversal#Flask#ImageMagick
Feb 16, 2025HackTheBox
MiscEasyWindows

HTB — Mailing

hMailServer path traversal leaks admin hash. Outlook CVE-2024-21413 moniker link attack for NTLM relay, WinPEAS finds privesc vector.

#hMailServer#NTLM Relay#CVE-2024-21413
Jan 16, 2025HackTheBox
WebEasyLinux

HTB — Chemistry

CIF file parser RCE via pymatgen CVE-2024-23346 arbitrary code execution. aiohttp path traversal CVE-2024-23334 for credential theft and lateral movement.

#CIF Parser#CVE-2024-23346#aiohttp
Jan 10, 2025HackTheBox