HackTheBox Writeups 26
- Writeup - CVE SQLi
- VulnEscape RDP misconfigured
- Vaccine ~ SQLi
- Support - Active Directory
- Sau - CVE
- Retro - Active Directory
- Reset - LFI on User-Agent to RCE
- Precious - Command injection
- Planning - CVE and exposed creds
- Paper - CVE
- Pandora - Exposed creds to SQLI to RCE
- Manage - Java RMI misconfigured
- Lock - Exposed Personal Access Token to aspx web shell and CVE
- Jerry - CVE
- GoodGame - SQLi and SSTI
- Expressway - VPN weak creds
- EscapeTwo - Active directory
- Driver - SMB config + weak creds
- Down - SSRF Protocol Filter Bypass leading to Arbitrary File Read
- Devvortex - CVE
- Conversor - XSLT injection to RCE
- Cicada - Active Directory
- Cap - Exposed Creds
- Broker - CVE
- Broadlight - CVE and weak creds
- Archetype - RCE