FireFlow Writeup - HackTheBox
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
HackIndex
Language
Showing 1–4 of 4
Flask web app vulnerable to SSTI via user-controlled templates. Exploit Jinja2 injection to achieve RCE, then escalate privileges on Linux for root.
Exploit a Flask SSTI vulnerability in a developer hub app to gain RCE, then escalate privileges via misconfigured sudo or SUID binaries on Linux.
SSTI via resume upload, exploiting a Flask/Jinja2 template injection in a smart hiring app to achieve RCE and capture the flag.
Exploiting JWT algorithm confusion and SSTI vulnerabilities on a Linux machine to escalate privileges and capture the flag.
Other platforms
We use cookies to improve your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Privacy Policy.