webPromedium

PageCraft — LFI to RCE via /proc/self/environ User-Agent Injection

hackadvisor

Task: PHP CMS with ?pg= parameter vulnerable to LFI via path traversal, no input sanitization on include(). Solution: Exploited LFI to include /proc/self/environ, injected PHP code via User-Agent header to achieve RCE and read /root/flag.txt.

$ ls tags/ techniques/
path_traversallfi_to_rceproc_self_environ_injectionuser_agent_code_injectionphp_include_exploitation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups