A user registration form on Spring Data Commons 2.0.5, vulnerable to CVE-2018-1273: request parameter names are bound to the projection through SpEL, so a crafted parameter name runs commands.
Pas commencéDockercommit c6bcda5x86_64 · aarch64Secret
Exploit CVE-2018-1273 to run commands on the Spring server and get a shell.
Le brief de ce lab se trouve dans son dépôt.