WordPress 4.6, vulnerable to PwnScriptum (CVE-2016-10033 in PHPMailer): the password reset form builds the sender address from the Host header, which goes to the sendmail (Exim) command line, where -be string expansion runs commands.
Pas commencéDockercommit 94320dax86_64 · aarch64Secret
Exploit PwnScriptum through the password reset form to run commands on the WordPress server and get a shell.
Le brief de ce lab se trouve dans son dépôt.