HackTheBox
16 entries · web / linux
-
Pre-auth Metabase 0.46.6 RCE via an H2 JDBC init trigger and a leaked setup-token (CVE-2023-38646) for a shell in a container, container env vars leak metalytics' reused SSH password, then the GameOver(lay) OverlayFS kernel flaw (CVE-2023-2640 / CVE-2023-32629) gives root.
-
Apache ActiveMQ 5.15.15 with admin:admin defaults, unauthenticated OpenWire deserialization RCE via a Spring ClassPathXmlApplicationContext bean (CVE-2023-46604) for a shell as activemq, then a sudo nginx root config with WebDAV PUT writes root's authorized_keys for root over SSH.
-
request-baskets 1.2.1 SSRF (CVE-2023-27163) proxies to an internal Maltrail 0.53, whose unauthenticated login command injection gives a shell as puma, then a sudo systemctl status pager escape spawns a root shell.
-
Default-credential foothold on a hidden Dolibarr 17.0.0 CRM via a case-bypass PHP injection (CVE-2023-30253), lateral movement through a database password reused for a system account, and root through the Enlightenment enlightenment_sys SUID binary (CVE-2022-37706).
-
Malicious Chrome extension upload to reach an internal service, Bash array-index command injection via unquoted argument, and privilege escalation via world-writable __pycache__ poisoning of a sudo-allowed Python script.
-
CVE-2025-47812 Lua injection in Wing FTP Server 7.4.3 gives RCE as wingftp, a cracked account hash reaches wacky over SSH, and a sudo backup-restore tar traversal plants an SSH key for root.
-
Unauthenticated RCE on the Pterodactyl Panel via CVE-2025-49132 path traversal and pearcmd, a cracked bcrypt hash from the MySQL users table to SSH as phileasfogg3, then the CVE-2025-6018 polkit bypass chained with the CVE-2025-6019 udisks2 XFS SUID mount for root.
-
Camaleon CMS mass-assignment (CVE-2025-2304) grants admin, leaking MinIO keys to an S3 bucket that holds an SSH key cracked for a trivia login, then a sudo facter external fact escalates to root.
-
The UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) gives a shell as ircd, a steghide-hidden password recovers djmardov, and a SUID viewuser binary running /tmp/listusers is hijacked for root.
-
Joomla CVE-2023-23752 API disclosure leaks admin creds, a template-editor webshell for a shell, a cracked bcrypt hash for the user, and an apport-cli sudo pager escape (CVE-2023-1326) for root.
-
SNMP community-string brute leaks an API password, a command injection in the MentorQuotes /admin/backup endpoint gives a shell, a Postgres COPY FROM PROGRAM RCE cracks a service hash for SSH, then an snmpd.conf credential and a james sudo /bin/sh reach root.
-
Blind SQL injection on the Laravel password-reset endpoint dumps and cracks the admin hash, an avatar upload webshell gives dash, a .monitrc password reaches xander, and a 7za listfile wildcard reads root.txt.
-
LFI in news.php leaks tomcat-users.xml, a WAR deploy through the Tomcat manager gives a shell, a cracked backup zip password logs in as ash, and lxd group membership mounts the host for root.
-
SQL injection in the hotel room page yields an os-shell as www-data, a sudo simpler.py command-substitution bypass pivots to pepper, and a SUID systemctl service escalates to root.
-
Escaped the vm2 3.9.16 Node.js sandbox (CVE-2023-30547) via the /editor endpoint for RCE, cracked joshua's bcrypt hash from a SQLite tickets.db, then abused an unquoted bash glob comparison in a sudo backup script to brute-force root's password character by character.
-
Hijacked kanderson's session from an exposed Spring Boot /actuator/sessions endpoint, injected a space-free reverse shell through the admin add-host feature for a foothold as app, cracked a postgres-stored admin bcrypt to josh's reused SSH password, then rooted via sudo ssh ProxyCommand.