deutche-telekom

1 article
sort: new top best
clear filter
0 7/10

A bug bounty writeup demonstrating LFI-to-RCE on Deutche Telekom via path traversal in help.php parameter, escalated to command execution through Apache error log poisoning by injecting PHP code via the referer header.

Deutche Telekom Daniel Maksimovic telekom.de netweb.telekom.de aquatone dnsenum recon-ng sublist3r BurpSuite dirb
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details