reverse-shell

2 articles
Sort: New Top Best
clear filter
0
vulnerability

A path traversal vulnerability in GitHub Desktop's x-github-client:// URI scheme handler allowed arbitrary code execution on macOS by opening malicious application bundles from a cloned repository without user interaction or Gatekeeper validation. The vulnerability was patched in GitHub Desktop v1.3.4.

GitHub Desktop H1-702 HackerOne 0xacb zhuowei CVE-2018-1000559 github-desktop-poc
pwning.re · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details
0
bug-bounty

A bug bounty researcher discovered RCE on an abandoned staging web service via an unauthenticated PUT HTTP method that allowed arbitrary file uploads, enabling PHP web shell deployment and subsequent internal network traversal with privilege escalation through credential reuse and weak security practices.

nmap ncat netcat PHP Python SSH RDP SMB DNS zone transfer
blog.zsec.uk · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details