webProhard
Photo Storage
miptctf
Flask photo storage with admin bot. CVE-2025-7066 MIME type bypass (image/gif;a=b,text/html) allows XSS via GIF+HTML polyglot. Chain: steal admin cookie -> CSRF to /admin/compress -> command injection in quality parameter -> exfiltrate $FLAG.
$ ls tags/ techniques/
cve_2025_7066_mime_bypassgif_html_polyglotsame_origin_xsscsrf_token_extractionshell_command_injection
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Ecler 2— spbctf
- [web][Pro]Knowledge Base— miptctf
- [web][Pro]Easy Upload— hackerlab
- [web][Pro]After Image— srdnlen
- [web][Pro]Museum— hackerlab