xsspresso
xsspresso
Tags/ Tomcat

Tomcat

2 writeups tagged with Tomcat

WebMediumWindows

VHL — AS45

Apache Tomcat 8.0.47 on Windows with AJP exposed. Exploited Ghostcat (CVE-2020-1938) via AJP connector to read sensitive files and gain RCE.

#Tomcat#Ghostcat#CVE-2020-1938
Feb 13, 2025Virtual Hacking Labs
WebEasyLinux

HTB — Tabby

LFI on Tomcat manager exposes credentials. WAR file deployed for RCE. ZIP password cracking, LXD container privilege escalation for root.

#LFI#Tomcat#WAR
Nov 26, 2024HackTheBox