Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How to Chain Vulnerabilities for RCE: From Image Metadata to Complete System Compromise

Summary

A CTF postmortem: five chained flaws — from exiftool metadata revealing wkhtmltopdf, through traversal, SSRF and command injection — produced an unauthenticated CVSS 10.0 RCE in 3h15m.
Published
Collected

original ↗

Related coverage

back