
CVE-2021-3456
A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance
command-and-controleducationexploitation+8

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.