
HTB-TwoMillion-Writeup
HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386
command-and-controlctfeducation+8

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Cockpit: Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection

Proof-of-concept exploit for Pi-Hole AdminLTE command injection (CVE-2019-13051) enabling remote root access via email field injection and cron-based…