xsspresso
xsspresso
Tags/ RCE

RCE

37 writeups tagged with RCE

WebMediumLinux

HTB — Conversor

Unit conversion web app vulnerable to server-side formula injection, leading to arbitrary OS command execution.

#Formula Injection#SSTI#RCE
Oct 25, 2025HackTheBox
WebMediumLinux

HTB — Expressway

Express.js prototype pollution vulnerability leads to remote code execution via deserialization of a crafted payload.

#Prototype Pollution#Node.js#Deserialization
Sep 27, 2025HackTheBox
WebMediumLinux

HTB — Cypher

Neo4j Cypher injection bypasses authentication. APOC procedure abuse executes OS commands for initial access and privesc.

#Cypher Injection#Neo4j#APOC
Mar 8, 2025HackTheBox
WebHardLinux

HTB — Checker

TeamCity authentication bypass combined with Bookstack SSRF to read internal files and chain into remote code execution.

#TeamCity#SSRF#Bookstack
Feb 22, 2025HackTheBox
WebMediumLinux

VHL — Tracker

MantisBT bug tracker on Debian with POP3. Credential enumeration via mail service and MantisBT RCE for shell access.

#MantisBT#POP3#Dovecot
Feb 19, 2025Virtual Hacking Labs
WebMediumLinux

VHL — PMV02

b2evolution blog CMS on Ubuntu. Authenticated file manager abuse and PHP filter injection lead to remote code execution.

#b2evolution#File Manager#PHP
Feb 17, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Graphs01

Cacti network monitoring on Ubuntu. Exploited CVE-2022-46169 unauthenticated RCE in Cacti for initial shell access.

#Cacti#CVE-2022-46169#RCE
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Mon02

Centreon IT monitoring platform on Red Hat. Default credentials lead to authenticated RCE via malicious poller command injection.

#Centreon#Default Creds#Command Injection
Feb 16, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS101

Joomla CMS on CentOS with ProFTPD. Exploited a known Joomla CVE for unauthenticated RCE via the com_media upload component.

#Joomla#CVE#RCE
Feb 15, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Code

Self-hosted GitLab CE on CentOS. Exploited CVE-2021-22205 unauthenticated RCE via image upload to the GitLab instance.

#GitLab#CVE-2021-22205#RCE
Feb 14, 2025Virtual Hacking Labs
WebEasyLinux

VHL — JS01

Jenkins CI/CD server with no authentication. Exploited the Groovy script console to execute commands and gain a root shell.

#Jenkins#Groovy#Script Console
Feb 14, 2025Virtual Hacking Labs
MiscMediumLinux

VHL — PBX

FreePBX/Asterisk VoIP server on Ubuntu. Exploited FreePBX RCE CVE via the admin panel to gain a reverse shell and escalate.

#FreePBX#Asterisk#VoIP
Feb 14, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS01

Joomla CMS on CentOS with anonymous FTP. Exploited a Joomla authenticated RCE CVE via the template editor for code execution.

#Joomla#RCE#FTP
Feb 13, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Tracking

Drupal 9 on Debian. Exploited an authenticated RCE vulnerability with compromised admin credentials found via enumeration.

#Drupal#RCE#Enumeration
Feb 13, 2025Virtual Hacking Labs
WebMediumLinux

VHL — Dolphin

Dolphin CMS with a WordPress instance on port 81. Admin credential brute-force leads to plugin RCE and privilege escalation.

#Dolphin CMS#WordPress#Brute Force
Feb 12, 2025Virtual Hacking Labs
WebEasyWindows

VHL — Anthony

Windows 7 SP1 with Apache and multiple services. Enumerated web application vulnerabilities and exploited weak credentials for admin access.

#Apache#Windows 7#Credential Enum
Feb 12, 2025Virtual Hacking Labs
WebMediumLinux

VHL — CMS02

Drupal 8 on CentOS. Exploited Drupalgeddon2 (CVE-2018-7600) for unauthenticated RCE and escalated privileges via SUID binary.

#Drupal#Drupalgeddon2#CVE-2018-7600
Feb 11, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Quick

Quick.CMS v6.7 with a known authenticated RCE vulnerability. Admin credentials discovered via enumeration for initial access.

#CMS#RCE#Quick.CMS
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Tiki

TikiWiki CMS Groupware on CentOS. Exploited a known CVE for unauthenticated remote code execution to gain a shell.

#TikiWiki#CMS#RCE
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — VPS1723

Webmin 1.991 on Ubuntu. CVE-2019-15107 arbitrary command execution via the password reset endpoint for instant root access.

#Webmin#CVE-2019-15107#RCE
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Helpdesk

FTP with anonymous access reveals helpdesk application credentials. SQL injection and file upload lead to remote code execution.

#FTP#SQLi#File Upload
Feb 10, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Forum

uftpd FTP server with anonymous access. Forum application vulnerability exploited to obtain a shell and escalate to root.

#FTP#uftpd#Forum
Feb 9, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Techblog

WordPress 4.7.2 on CentOS. Exploited outdated plugin for remote code execution and escalated via sudo misconfiguration.

#WordPress#RCE#Sudo
Feb 8, 2025Virtual Hacking Labs
WebEasyLinux

HTB — OpenAdmin

OpenNetAdmin 18.1.1 RCE via command injection in web console. Internal Apache vhost with SSH key in password-protected page for lateral movement.

#OpenNetAdmin#Command Injection#RCE
Jan 18, 2025HackTheBox
WebEasyLinux

HTB — Devvortex

Joomla CVE-2023-23752 info disclosure leaks database creds. Authenticated template RCE for shell. Apport crash handler sudo exploit for root.

#Joomla#CVE-2023-23752#RCE
Jan 16, 2025HackTheBox
WebEasyWindows

HTB — Love

SSRF on a voting system bypasses firewall to reach internal file analysis service. PHP file upload for RCE, AlwaysInstallElevated for SYSTEM.

#SSRF#File Upload#AlwaysInstallElevated
Jan 16, 2025HackTheBox
WebEasyWindows

HTB — Buff

Gym Management Software RCE via unauthenticated file upload. CloudMe buffer overflow with port forwarding for privilege escalation.

#File Upload#RCE#Buffer Overflow
Jan 15, 2025HackTheBox
WebEasyLinux

HTB — Sea

WonderCMS CVE-2023-41425 XSS to RCE via theme upload. Credential reuse for lateral movement. Port-forwarded internal tool for command injection privesc.

#WonderCMS#XSS#RCE
Jan 14, 2025HackTheBox
WebEasyWindows

HTB — Remote

Umbraco CMS with anonymous NFS mount exposing credentials. Authenticated SXSS/RCE via template. TeamViewer 7 password decryption for SYSTEM.

#Umbraco#NFS#RCE
Jan 14, 2025HackTheBox
WebMediumLinux

HTB — Heal

ResumeAI app with IDOR exposing all resumes. LimeSurvey RCE via authenticated plugin upload. Consul service token for SYSTEM shell via API exec.

#IDOR#LimeSurvey#Consul
Jan 11, 2025HackTheBox
WebEasyLinux

HTB — CozyHosting

Spring Boot Actuator exposes session cookies. Hijacked admin session to exploit command injection in SSH endpoint for reverse shell.

#Spring Boot#Actuator#Command Injection
Nov 26, 2024HackTheBox
WebEasyLinux

HTB — Knife

PHP 8.1.0-dev backdoor via User-Agentt header for RCE. Sudo knife binary used as a GTFOBin for instant root shell.

#PHP Backdoor#RCE#GTFOBins
Nov 25, 2024HackTheBox
WebMediumWindows

HTB — Bastard

Drupal 7 authenticated RCE via Services module REST endpoint. MS15-051 kernel exploit escalates to SYSTEM.

#Drupal#RCE#REST API
May 20, 2022HackTheBox
WebEasyWindows

HTB — Optimum

HttpFileServer 2.3 RCE (CVE-2014-6287) via Rejetto HFS. Windows kernel exploit (MS16-032) for privilege escalation to SYSTEM.

#HFS#CVE-2014-6287#RCE
May 16, 2022HackTheBox
WebEasyLinux

HTB — Swagshop

Magento 1.9 SQLi creates an admin account; Magento Froghopper achieves RCE. Sudo vim executes a shell as root.

#Magento#SQLi#RCE
Apr 13, 2022HackTheBox
WebEasyLinux

HTB — Nibbles

Nibbleblog CMS with guessable admin credentials leads to arbitrary PHP file upload and remote code execution.

#Nibbleblog#File Upload#RCE
Mar 25, 2022HackTheBox
MiscEasyLinux

HTB — Lame

The first HTB machine. Single Samba 3.0.20 exploit (CVE-2007-2447) for an instant root shell via username map script.

#Samba#CVE-2007-2447#RCE
Mar 3, 2022HackTheBox