An Apache and PHP web root with PHPUnit 5.6.2 left in vendor/, vulnerable to CVE-2017-9841: Util/PHP/eval-stdin.php runs `eval()` on php://input, so a POST body starting with <?php runs code.
Pas commencéDockercommit 2fe4fa7x86_64 · aarch64Secret
Exploit CVE-2017-9841 to run code on the web server and get a shell.
Le brief de ce lab se trouve dans son dépôt.