xsspresso
xsspresso
Tags/ Spring Boot

Spring Boot

1 writeup tagged with Spring Boot

WebEasyLinux

HTB — CozyHosting

Spring Boot Actuator exposes session cookies. Hijacked admin session to exploit command injection in SSH endpoint for reverse shell.

#Spring Boot#Actuator#Command Injection
Nov 26, 2024HackTheBox