public-key-authentication

1 article
sort: new top best
clear filter
0 6/10

A bug bounty writeup demonstrating exploitation of Apache Struts CVE-2013-2251 (OGNL injection) against a travel booking website, bypassing WAF detection by embedding the malicious payload within a redirect parameter, followed by privilege escalation to root via kernel CVE-2013-2094 using reverse SSH tunneling.

CVE-2013-2251 CVE-2013-2094 Apache Struts 2.3.15 Avinash Jain Kunal Aggarwal
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details