phpMyAdmin 4.8.1, vulnerable to CVE-2018-12613: the target parameter of index.php passes a whitelist check that URL-decodes it, then includes the raw path, so a crafted value includes any local file, such as a session file holding PHP code.
Not startedDockercommit 756a638x86_64 · aarch64Secret
Exploit CVE-2018-12613 to include a local file, then run a command on the server.
The brief for this lab lives in its repository.