Apache Tomcat 8.5.19 with the default servlet's readonly set to false, vulnerable to CVE-2017-12615: an HTTP PUT with a crafted file name writes a JSP file to the web root.
Pas commencéDockercommit 3716006x86_64 · aarch64Secret
Exploit CVE-2017-12615 to upload a JSP web shell, run a command on the server and read /ctf/flag.
Le brief de ce lab se trouve dans son dépôt.