phpMyAdmin 4.8.1, vulnerable to CVE-2018-12613: the target parameter of index.php passes a whitelist check that URL-decodes it, then includes the raw path, so a crafted value includes any local file, such as a session file holding PHP code.
Pas commencéDockercommit 9be2d0bx86_64 · aarch64Secret
Exploit CVE-2018-12613 to include a local file through phpMyAdmin, run a command on the web server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.